What Happened to HackerOne?
Once a community-centric bug bounty platform, HackerOne is portrayed as drifting toward a sales- and AI-driven enterprise product strategy, leaving many security researchers feeling sidelined. Commenters highlight how venture capital pressures, low margins, and a flood of low-quality or AI-generated reports have pushed the company toward automated triage and paid “AI pentest” offerings, often at the perceived expense of transparency, responsiveness, and fair treatment. At the same time, several voices note that platforms like HackerOne still solve hard problems around global payments, legal risk, and noise filtering, making them difficult for large organizations to replace outright despite growing frustration.
Perceived Decline of HackerOne
- Many see a classic “enshittification” arc: early mission-driven community focus giving way to revenue optimization, bureaucracy, and investor pressure.
- Shift from bug bounties and live hacking events toward AI security products and “continuous testing” is viewed as a pivot away from the hacker community that built the platform.
- Some argue this is less about “corruption” and more about thin margins, economics, and COVID-era budget cuts that killed in-person events and never fully returned.
AI Use, LLM Triage, and Trust
- Strong backlash to obviously AI-generated “PR responses” from leadership; some see this as a reputational tipping point and sign of not caring about the community.
- Dispute over whether HackerOne misled hackers about using reports to train AI:
- One side: training on bounty reports for in-house AI products breaks promises and exploits community work.
- Other side: distinction between model training vs using reports as context/tools means the claims may technically be compatible; controversy seen as overblown.
- Practitioners report AI triage is decent at severity ranking but poor at validating whether a bug is real; skepticism about “LLM slop” triaging “LLM slop.”
Bug Bounty Experience and Frictions
- Many researchers report issues being dismissed, downgraded (especially DoS), or left unresolved for years, even when severity seems high to them.
- Strong disagreement on DoS severity: some treat it as low by default; others argue single-client global outages are business-critical.
- Reports of companies effectively baiting researchers to perform illegal-scale attacks to “prove” impact, increasing legal risk and mistrust.
- Some say platforms and big vendors sometimes optimize metrics over collaboration, damaging relationships and leading to informal blacklisting.
Business Model, Sales Culture, and VC
- Bug bounty triage is expensive, especially with AI-generated spam; margins are described as weak, driving diversification into AI pentest products.
- Sales-first culture and “presidents club” tropical trips are defended as standard enterprise practice, but others see it as symbolizing focus on selling a deteriorating product.
Role and Value of Platforms vs In‑House
- Despite criticism, many stress the core value of platforms: global payments, sanctions/compliance, tax handling, and pre-triage.
- Crypto/stablecoins and payment services are proposed alternatives, but others highlight banking resistance, tax complexity, and legal risk.
- Some think companies could replace platforms with in-house tooling plus AI; others argue SaaS will remain attractive because it makes hard, evolving problems “go away.”
Ecosystem & Future Direction
- Bug bounty programs were already flooded with low-effort reports; LLMs reportedly pushed false-positive rates much higher.
- Platforms are compared to “LinkedIn for hacking”: useful for reputation-building, recruiting, and community—but seen as underleveraging community events and profiling.
- Overall sentiment: bug bounty platforms remain useful but are drifting from their original hacker-centric mission under economic and AI-driven pressures.