Twitter Has Paid Out $322,420 in Its 'HackerOne' Bug Bounty Programme

Advertisement
By Indo-Asian News Service | Updated: 28 May 2016 16:46 IST
Micro-blogging website Twitter has paid $322,420 (roughly Rs. 2.1 crores) to researchers and bug hunters who, under its bug bounty "HackerOne" program, have disclosed vulnerabilities in the last two years.

"We maintain a secure development lifecycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services - all to maximise the security we provide to our users," Arkadiy Tetelman, software engineer at Twitter, said in a blog post on Friday.

On top of these measures, the company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can can respond and address these issues before they are exploited by others.

Advertisement

The company has been utilising "HackerOne" since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.

He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 percent of resolved bugs were publicly disclosed (at the request of the researcher).

Advertisement

"We have paid out a total of $322,420 (USD) to researchers. Our average payout is $835. Our minimum payout is $140 and our highest payout to date was $12,040 (our payouts are always a multiple of 140)," Tetelman noted.

In 2015 alone, a single researcher made over $54,000 (roughly Rs. 36 lakhs) for reporting vulnerabilities, the software engineer said.

Advertisement

"We also offer a minimum of $15,000 (roughly Rs. 10 lakhs) for remote code execution vulnerabilities, but we have yet to receive such a report," he added.

Tetelman noted some great bugs exposed through the program, including XSS inside Crashlytics Android app that renders part of its content inside a webview, which did not have adequate protection against cross site scripting attacks.

Advertisement

He also mentioned "IDOR allowing credit card deletion" -- a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.

"If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!" he said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Anthropic's AI-Powered Claude Design Is Here to Take on Figma
  2. OnePlus Nord CE 6, Nord CE 6 Lite Will Launch in India on This Date
  3. Huawei Watch Fit 5 Series Debuts With AMOLED Displays, HarmonyOS: See Price
  4. Dell 15 Refreshed With Up to Intel Core Ultra 7, 15.6-Inch Display
  5. Poco C81, C81x to Launch in India With Up to 6,300mAh Battery on This Date
  6. Motorola Razr 2026, Razr+ 2026 Launch Date, Price, Specifications Leaked
  7. Xiaomi 18 Pro Max Tipped to Sport a Large Display and This Snapdragon Chip
  8. OnePlus Nord CE 6 Visits Geekbench With These Specifications
  1. Blue Origin Reuses New Glenn Booster for First Time in Historic Launch
  2. Motorola Razr 2026, Razr+ 2026 Launch Date, Price, Specifications Leaked
  3. Huawei Watch Buds 2 Launched With Built-in Earbuds, LTPO Display: Price, Features
  4. Adobe Introduces CX Enterprise, an Agentic AI Platform to Automate Customer Experience for Businesses
  5. Infinix GT 50 Pro Global Launch Date Announced; Will Debut With Liquid Cooling, Pressure-Sensitive Triggers
  6. Huawei Watch Fit 5, Watch Fit 5 Pro Launched With AMOLED Screens, HarmonyOS and Up to 10 Days Battery Life
  7. Apple Withholds Data in India Antitrust Case, CCI Sets Final Hearing
  8. Anthropic Introduces Claude Design, an AI Tool to Generate Visual Prototypes and Pitch Decks
  9. Nee Forever OTT Release Date: When and Where to Watch This Tamil Romantic Drama Online?
  10. Huawei Pura 90 Pro Max Launched With 200-Megapixel Telephoto Camera Alongside Huawei Pura 90, Pura 90 Pro
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.