A longtime bug-bounty researcher and program manager has published a sharply critical account of HackerOne's evolution, arguing that the platform moved away from its original researcher-centered mission toward enterprise sales and AI-branded services. The article is a personal assessment based on work on both sides of the platform, not an independent audit of the company.
The author joined HackerOne as a researcher in 2017 and managed multiple large programs from 2018 through 2025. The essay traces HackerOne's origin to ethical hackers Jobert Abma and Michiel Prins, who began reporting vulnerabilities to major technology companies in 2011. Bug-bounty platforms created a consent-based channel where researchers could disclose flaws and receive payment with less legal uncertainty.
From 2017 to 2020, HackerOne ran frequent live hacking events that brought leading researchers together around selected targets. The author says those short events produced large numbers of serious reports and helped form relationships in a previously fragmented community. Regional groups, meetups, workshops and capture-the-flag events extended that network.
The essay says those programs later lost momentum, experienced staff departed and event invitations became more exclusive and calculated. It links the change to pressure for revenue after years of venture funding, citing $160 million raised between 2014 and 2022. HackerOne moved from taking a 20 percent share of bounty payments toward capacity pricing, annual contracts and multi-year agreements, according to the account.
A Hacker Success Program gave selected top researchers direct help with disputes, communication and payouts. The author acknowledges that this support resolved problems for participants, but argues it created a two-tier system because newcomers lacked the same advocacy and platform feedback rarely led to product changes.
The critique becomes more pointed around AI. It says HackerOne built Hai, described by the author as an OpenAI-based assistant, rather than using new development tools to address a backlog of requested platform features. The company also rebranded around continuous threat exposure management and agentic penetration testing.
The article recounts concern over 2026 terms that appeared to permit use of reports for AI training. HackerOne co-founder Alex Rice and chief executive Kara Sprague publicly said researcher submissions and confidential customer data were not used to train or improve generative models, including Hai and Agentic PTaaS.
Those denials are important context, as are the source's openly adversarial tone and lack of a separate company response to its broader conclusions. The report documents one experienced participant's loss of confidence and specific changes he observed. It does not establish that HackerOne has collapsed, but it shows how a platform's commercial strategy can alienate contributors who viewed community trust as its core product.


