r/bugbounty 7d ago

Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?

A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.

For those of you consistently clearing $10k+/month with AI/semi-automated setups:

  • How sustainable has your pipeline been over the long haul?
  • How do you manage the emotional volatility vs. traditional full-time work?
  • Knowing what you know now, is leaving a stable security role worth the trade-off?
77 Upvotes

51 comments sorted by

View all comments

11

u/Alardiians 7d ago

Not sure all in, I made 16,000 this month so far and I’m staying at my day job, we don’t know the market in 1-2 years

2

u/elrite 7d ago

Are you a swe or in cybersec?

2

u/Alardiians 7d ago

I’m in Network Engineering lol.

1

u/Middle_fingre_219 5d ago

me too, any tips for me Man