Twitter Has Paid Out $322,420 in Its 'HackerOne' Bug Bounty Programme

Advertisement
By Indo-Asian News Service | Updated: 28 May 2016 16:46 IST
Micro-blogging website Twitter has paid $322,420 (roughly Rs. 2.1 crores) to researchers and bug hunters who, under its bug bounty "HackerOne" program, have disclosed vulnerabilities in the last two years.

"We maintain a secure development lifecycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services - all to maximise the security we provide to our users," Arkadiy Tetelman, software engineer at Twitter, said in a blog post on Friday.

On top of these measures, the company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can can respond and address these issues before they are exploited by others.

The company has been utilising "HackerOne" since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.

Advertisement

He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 percent of resolved bugs were publicly disclosed (at the request of the researcher).

Advertisement

"We have paid out a total of $322,420 (USD) to researchers. Our average payout is $835. Our minimum payout is $140 and our highest payout to date was $12,040 (our payouts are always a multiple of 140)," Tetelman noted.

In 2015 alone, a single researcher made over $54,000 (roughly Rs. 36 lakhs) for reporting vulnerabilities, the software engineer said.

Advertisement

"We also offer a minimum of $15,000 (roughly Rs. 10 lakhs) for remote code execution vulnerabilities, but we have yet to receive such a report," he added.

Tetelman noted some great bugs exposed through the program, including XSS inside Crashlytics Android app that renders part of its content inside a webview, which did not have adequate protection against cross site scripting attacks.

Advertisement

He also mentioned "IDOR allowing credit card deletion" -- a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.

"If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!" he said.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  2. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  3. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  4. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  5. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  6. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  7. WhatsApp Plus Could Soon Let You Pay to Access These Features
  8. Vivo X300 FE Launched as Global Version of This Chinese Smartphone
  9. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  10. Samsung Galaxy A37, Galaxy A57 Get Better Geekbench Scores Ahead of Debut
  1. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  2. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  3. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  4. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  5. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  6. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  7. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
  8. Nothing Phone 4a Launched in India With Glyph Bar Interface Alongside Nothing Phone 4a Pro: Price, Specs
  9. Oppo Find N6 Key Features, Colour Options Leaked Ahead of Imminent China Launch
  10. Honor 600 Lite Launched With MediaTek Dimensity 7100 Elite, 6,520mAh Battery: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.