NewsSecurity

HackerOne Requires ID by Aug 14: What Researchers Must Do

HackerOne mandatory ID verification shield with fingerprint scan showing bug bounty researcher identity requirement

HackerOne is requiring government-issued ID from every researcher submitting to a paid bug bounty program, effective August 14. That’s four days from now. If you hunt bugs on HackerOne and haven’t verified your identity with Veriff yet, you’ll lose access to every Bug Bounty Program on the platform the moment that deadline hits. Vulnerability Disclosure Programs (VDPs) are unaffected — this only applies if you’re submitting for monetary rewards.

HackerOne ID Verification: What the Policy Requires

Starting August 14, submitting to any Bug Bounty Program (BBP) requires completing KYC through Veriff, HackerOne’s identity verification provider. You’ll need a physical, unexpired government document — passport, driver’s license, national ID, or residence permit. No photocopies. No digital scans. During the verification session, HackerOne explicitly bans VPNs, traffic anonymizers, jailbroken devices, SDK emulators, and iOS Private Relay. Veriff confirms the session immediately; HackerOne sends final status within three business days. Verification expires annually.

If you’re on HackerOne purely for VDPs — programs that accept reports without offering payment — nothing changes. The two-tier structure is now explicit: open access for disclosures that help the public, verified identity required for disclosures that earn you money.

If you’re an active bug bounty researcher on HackerOne, start the verification process today. Three business days puts you right at the August 14 cutoff, and there’s no grace period mentioned in the announcement.

Related: AI Slop Is Killing Bug Bounty Programs — Act Now

Why Bug Bounty Platforms Are in Crisis

This policy didn’t emerge in a vacuum. HackerOne saw a 76% jump in submissions year-over-year through March 2026. Of those, only about 25% flagged real vulnerabilities. Invalid submission rates across the industry jumped from roughly 30% to 50–65%. Triage teams went from spending 4–6 hours per report to 8–14 hours. The math doesn’t work when the majority of your queue is AI-generated garbage.

The casualties tell the story: curl ended its bug bounty program entirely in January after being overwhelmed by hallucinated vulnerability reports. HackerOne paused its own Internet Bug Bounty in March. Nextcloud shut down its program in April. In July, GitHub slashed public payouts by 50% and moved top-tier rewards into an invite-only program. The bug bounty industry spent the first half of 2026 watching the economics collapse under the weight of agentic AI tools that could flood a platform with plausible-looking nonsense at scale.

The Privacy Argument Is Real, But So Is the Alternative

The obvious objection: bug bounty culture was built on pseudonymous disclosure. Security researchers — particularly independent researchers, those working in politically sensitive regions, and privacy-first practitioners — operated under handles specifically to separate their professional work from their legal identity. The ban on VPNs and anonymizers during verification isn’t incidental. It’s designed to make identity verification irreversible and unambiguous, which is exactly what privacy-conscious researchers object to.

HackerOne frames the mandate as protecting researcher reputation — tying your findings to your verified identity creates accountability and credibility. The counterargument is that it also creates risk. A researcher who exposes a politically connected organization’s vulnerability is now doing so with their legal name on file at a third-party KYC vendor. That’s a meaningful change for some subset of the global research community.

That said, the alternative was platform death by noise. According to analysis of the 2026 CVE flood, CEO Kara Sprague put it plainly: “Discovery is not the edge anymore; closing speed is.” When 75% of submissions are garbage, the signal drowns. Some researchers welcome the mandate for exactly that reason — one practitioner noted on Threads that AI-powered agentic tools had “made it harder for legitimate reports to get through” by flooding platforms with volume.

Bug Bounty Is Professionalizing — Whether Researchers Like It or Not

Look at what’s emerged: GitHub now has a public tier with capped payouts and a vetted VIP tier with higher rewards. HackerOne has open VDPs for everyone and gated BBPs for the verified. The model is converging toward professional credentialing rather than grassroots crowd-sourcing. Bug bounty started as a way to harness the distributed talent of anonymous researchers who wouldn’t otherwise participate in formal security programs. The new model favors established professionals who are already verified through other channels.

Alternatives exist if the ID requirement is a dealbreaker. Bugcrowd hasn’t announced a similar mandate and has positioned itself as researcher-friendly, explicitly prohibiting third parties from training AI on researcher submissions. Intigriti, the European platform, operates under GDPR and has emphasized researcher data ownership. Neither platform has fully solved the AI spam problem discussed across the security community — so expect the pressure to reach them too.

Key Takeaways

  • Action required by August 14: HackerOne bug bounty researchers must complete identity verification via Veriff. Start today — final confirmation takes up to three business days.
  • VDPs are not affected: If you submit vulnerability disclosures without seeking payment, nothing changes.
  • The AI spam crisis is real: 76% more submissions, only 25% valid findings. Platforms were drowning — this is a structural response, not a surprise.
  • Privacy trade-off is legitimate: The VPN ban during verification signals this is a hard ID requirement, not a soft one. Anonymous bug bounty on HackerOne BBPs is effectively over.
  • Alternatives exist: Bugcrowd and Intigriti haven’t followed suit yet. But if HackerOne’s quality improves, expect the rest of the industry to consider it.
ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News