Ukraine Ethical Hackers Bewildered as HackerOne Bug Bounty Platform Said to Halt Their Payouts

HackerOne has allegedly halted the payouts of thousands of dollars for ethical hackers in Ukraine.

Advertisement
By Jagmeet Singh | Updated: 17 March 2022 16:16 IST
Highlights
  • HackerOne has halted payouts for Ukrainian ethical hackers
  • Ukrainian ethical hackers have no clarity on the update
  • HackerOne recently imposed restrictions for hackers in Russia and Belarus

Some ethical hackers consider platforms including HackerOne as their primary source of income

Photo Credit: Unsplash/ Kevin Ku

Amid the ongoing disruption from Russia, some ethical hackers in Ukraine are feeling lost as bug bounty platform HackerOne has allegedly withheld their payouts. The loss due to the sudden halt is said to have mounted to hundreds and thousands of dollars. A few of the affected ethical hackers — also known as cybersecurity researchers — have taken the issue to social media. Some of them have also written to the platform to get clarity on why exactly it has disabled their payments in the middle of the humanitarian catastrophe in the country.

Ethical hackers normally earn payouts ranging from tens and hundreds to over millions of dollars in the form of rewards through bug bounty platforms for reporting flaws in various Internet-based solutions. However, HackerOne is said to have suddenly stopped payouts for some Ukrainian hackers.

Earlier this month, HackerOne CEO Marten Mickos had announced, "[A]s we work to comply with the new sanctions, we'll withdraw all programmes for customers based in Russia, Belarus, and the occupied areas of Ukraine." On Monday, he clarified that the restrictions were for sanctioned regions - Russia and Belarus, not mentioning any clear details about the status of Ukraine.

Advertisement

“That's a really weird situation,” said independent security researcher Bob Diachenko, who has been associated with the San Francisco, California-based platform for the last two–three years now.

Advertisement

The security researcher tweeted on Sunday that HackerOne stopped paying bounties worth around $3,000 (roughly Rs. 2,30,000) for the flaws he reported.

Alongside stopping payouts, HackerOne has removed its ‘Clear' status from all Ukraine accounts. The status essentially allows ethical hackers to participate in private programmes run by various companies to earn a minimum of $2,000 (roughly Rs. 1,53,100) for a high-severity vulnerability or $5,000 (roughly Rs. 3,82,800) for a critical one. It requires background-check for researchers to participate in the listed programmes.

Advertisement

 

“HackerOne was the primary source of income for me and many other researchers,” said independent security researcher Nick Mykhailyshyn. “Stopping payments even for a few weeks can put many people at risk.”

Advertisement

Mykhailyshyn wrote to the support team at HackerOne to understand whether his payouts were mistakenly blocked and the ‘Clear' status was accidentally removed. He shared a screenshot with Gadgets 360 where the team is seen responding by saying that the company was “exploring available options to reinstate a background check update and reinitiate you into Clear, pending updated results.”

The response also noted, “We recognise that this is extremely frustrating for you and we are working diligently to resolve and ensure that we adhere to the US economic sanctions and export controls.”

Another hacker, Vladimir Metnew, shared a screenshot of a HackerOne support email sent to him, which said all communications and transactions have been paused to those based in Ukraine, Russia, and Belarus.

At the time of announcing the initial restrictions earlier this month, HackerOne announced a donation of $25,000 (roughly Rs. 19,14,300) to United Nations Children's Fund (UNICEF) and planned to match donations dollar for dollar up to $100,000 (roughly Rs. 76,57,300) for the next three months to support people in the war-affected Ukraine.

On Monday, HackerOne CEO Mickos additionally said that the company was running hackers through additional screening based on sanction rules.

“Sanctions are worded to cover broad areas of finance and business. They were not written with ethical hacking in mind. They also are updated often. Interpreting sanctions is complicated. We have internal and external experts working on it,” Mickos said, adding that he apologised for the delay and the inconvenience caused to the hackers on the platform.

The executive, however, did not provide any clarity on whether the earned payouts of Ukrainian researchers were disabled intentionally.

Gadgets 360 reached out to HackerOne for a comment on the matter, and its Chief Hacking Officer and CISO Chris Evans acknowledged delays in payments for some Ukrainian hackers.

"On behalf of everyone at HackerOne, I am truly sorry for how our poor communication has caused confusion and undue stress for the Ukrainian hacker community," Evans said in a prepared statement. "We have not, and will not, block lawful payments to Ukrainian hackers. We actively support Ukraine's fight for freedom. There have been delays in backend payment systems for some Ukrainian hackers. This situation was then understandably conflated with generally inaccurate communications to hackers. Our teams are working to minimise these delays."

The CISO also reiterated that HackerOne was not automatically donating any bounty payments to UNICEF or any other charity. "We donate hackers' rewards to charity only on their instruction," he said.

However, Evans' statement shared by HackerOne doesn't give any clarity on the sudden removal of the 'Clear' status for Ukrainian researchers.

On how it is addressing the revoking of the ‘Clear' status for Ukrainian researchers, HackerOne redirected Gadgets 360 to an FAQ page that says the Chief Hacking Officer is reaching out to resolve the issue and expedite the background screening for the status.

“Our 15 Ukrainian hackers with Cleared status received a poorly worded communication about additional background screening,” the FAQ page noted.

HackerOne is one of the popular bug bounty platforms among ethical hackers around the world. It has over one million registered hackers on board that received a total of $40 million (roughly Rs. 306 crore) in 2020 alone, according to the company's internal report.


This week on Orbital, the Gadgets 360 podcast, we dive into Apple's Peek Performance event. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  3. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  4. GTA 6 Map Guide: Here's All You Need to Know About Different Areas
  5. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  6. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  7. You Can Now Vibe Code AI Mini Apps Within Gemini With This Tool
  8. Samsung Will Unveil These New Bespoke AI Devices at CES 2026
  9. Best ANC TWS Earbuds Under Rs 8,000: Sony WF-C710N, OnePlus Buds 4, More
  10. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.