frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Bugbop – a smaller bug bounty platform

https://bugbop.com
1•ponny•1h ago
Hi HN!

I created Bugbop over the last year now I'm officially releasing it! It’s a platform for teams that want to run their first bug bounty without expensive contracts. I come from a SaaS technical founder background where I ran our program for years. Now I've decided to make something better suited to that niche.

The model is simple: only pay when valid vulnerabilities are found. No ongoing subscriptions. Set budgets to avoid going over. The app's still in the early days but it's working: security bugs are getting paid and bug hunters are getting bounties.

It's using AI to review check if it's in scope, detect duplicates, and set severity (the app doesn't ask reporters because everyone just says "Critical").

I’m interested in feedback from people who’ve run bug bounties, stopped running them, or considered them and decided against it.

Comments

ponny•1h ago
Happy to answer any questions or just talk bug bounty/disclosure. I love both economics and security. Bug bounty sits at the intersection of these two.
colesantiago•1h ago
What makes this different to Hackerone or better yet, privately sending bounties to hackers off platform bypassing the fee?

Or someone else cloning the same thing as Bugbop with AI and undercutting it or making it free?

What is the actual indisputable USP of your solution?

ponny•44m ago
Fair questions.

The main differentiator to HackerOne is price and lower commitment (i.e. contracts). It's also a lot simpler in the UI as it's not chasing the big end of town and uses AI in a more integrated way. That said, Bugbop isn’t trying to replace HackerOne. It’s built for teams that won’t run a bug bounty otherwise.

Bypassing can be a problem but paying people overseas (and KYC) can be quite annoying. There's also less credibility without a 3rd party proving the bounties exist.

"Someone can copy you" was never going to be a moat. There's a lot more to a company than just the technical build. I'll just have to stay better than them :-)

I've priced Bugbop very competitively and making it free will be difficult with the payment processing fees.

Indisputable USP? That's hard. I think Bugbop is fairly unique in that it's a passion project of a long-time bug bounty program runner. I love this stuff and I'm happy to have a founder-to-founder calls about what bug bounty looks like in practice.

Show HN: Ginny and Georgia Test

https://ginnyandgeorgiatest.com/
1•zoooey•1m ago•0 comments

Exponential growth continued – cargo-semver-checks 2025 Year in Review

https://predr.ag/blog/cargo-semver-checks-2025-year-in-review/
1•agluszak•1m ago•0 comments

Stoat: An open-source, user-first chat platform

https://github.com/stoatchat
1•fanf2•1m ago•0 comments

Island of Misfit Startups: Part I (LensReader)

https://colinsteele.org/blog/island_of_misfit_startups_part_i_lensreader/
1•cvillecsteele•6m ago•0 comments

GCC 16 Compiler Steps Closer To Release With Algol 68 Front end, Zen 6, C++20

https://www.phoronix.com/news/GCC-16-Stage-4-Development
2•rbanffy•8m ago•0 comments

Justice Delayed Is Justice Denied

https://en.wikipedia.org/wiki/Justice_delayed_is_justice_denied
1•barrister•8m ago•0 comments

Show HN: QPost – Free tool for automating YouTube/TikTok/Instagram video posting

https://qpost.dev/
1•arslan2012•9m ago•0 comments

SpaceX gets FCC permission to launch another 7,500 Starlink satellites

https://arstechnica.com/tech-policy/2026/01/spacex-gets-fcc-permission-to-launch-another-7500-sta...
1•rbanffy•10m ago•0 comments

X Corp Sues Music Publishers, Alleges Coordinated DMCA Extortion

https://torrentfreak.com/x-sues-music-publishers-over-weaponized-dmca-takedown-conspiracy/
1•isaacfrond•11m ago•0 comments

The Homepage of Ron Goodwin

http://rongoodwin.co.uk/
1•ocfnash•12m ago•0 comments

Time Is of the Essence

https://docs.eventsourcingdb.io/blog/2026/01/12/time-is-of-the-essence/
1•goloroden•13m ago•0 comments

Show HN: Home Design AI

https://homedesign-ai.net
1•zoooey•13m ago•0 comments

Cosmotechnics and AI: Reading Hamid Ismailov's We Computers

https://seanvoisen.com/writing/cosmotechnics-and-ai/
1•tobr•14m ago•0 comments

Universal Commerce Protocol (UCP)

https://developers.googleblog.com/en/under-the-hood-universal-commerce-protocol-ucp/
1•topper00_raptor•16m ago•0 comments

US Nightmare Propaganda

https://twitter.com/i/status/2010826442725056648
1•barrister•17m ago•0 comments

Vibe Coding Debt: The Security Risks of AI-Generated Codebases

https://instatunnel.my/blog/vibe-coding-debt-the-security-risks-of-ai-generated-codebases
2•birdculture•19m ago•0 comments

Even Linus Torvalds is vibe coding now

https://www.zdnet.com/article/linus-torvalds-vibe-coding-ai/
3•isaacfrond•20m ago•0 comments

Working with Ruby Threads

https://workingwithruby.com/wwrt/intro
3•gmac•20m ago•2 comments

The Day AI Defeated Google (As Its Own Owner)

https://ai-404.medium.com/the-day-ai-defeated-google-as-its-own-owner-2fc1372cd2cc
2•martinambrus•21m ago•0 comments

Operation Tailwind War Crime

https://en.wikipedia.org/wiki/Operation_Tailwind
2•barrister•21m ago•0 comments

macOS 26's Cut Corners

https://daringfireball.net/2026/01/resizing_windows_macos_26
3•7777777phil•24m ago•0 comments

Burroughs B21 / Convergent AWS Vintage Computer Restoration – Dr. Scott M. Baker

https://www.smbaker.com/burroughs-b21-convergent-aws-vintage-computer-restoration
2•rbanffy•25m ago•0 comments

My AI resources packed together

https://mind-sculptor-engine.lovable.app/
2•tvali•27m ago•1 comments

I asked Opus 4.5 to make a Rust implementation of PyNNDescent

https://twitter.com/leland_mcinnes/status/2009738982712627433
2•tomthe•29m ago•1 comments

The Foundation Every Design System Gets Wrong

https://www.designsystemscollective.com/spacing-systems-the-foundation-every-design-system-gets-w...
3•vednig•31m ago•0 comments

Klarna boss backs interest rate cap on credit cards

https://www.thetimes.com/business/companies-markets/article/klarna-boss-backs-trump-10-percent-in...
2•petethomas•33m ago•0 comments

Show HN: Oubli – Persistent fractal memory for Claude Code

https://github.com/dremok/oubli
2•dremok•38m ago•0 comments

Helping promote the Lax programming language

2•Mavox-ID•49m ago•3 comments

Show HN: Stove – Kotlin-first E2E testing for JVM Back end apps(Ktor,SpringBoot)

https://github.com/Trendyol/stove
1•osoykan•49m ago•0 comments

In Memoriam: The Academic Journal

https://ieeexplore.ieee.org/document/11134631
1•jruohonen•50m ago•0 comments