An Ethical Hacker's Freelance Journey: Rs 1.2 Lakh from Bug Bounty
The email subject line just said "Triage Update." I opened it expecting another rejection.
It read: "Duplicate. Reported 9 hours prior to your submission." Nine hours. Somebody else found the exact same authentication bypass nine hours before I did, on a program I'd been watching for two weeks.
I closed the laptop and didn't open it again for three days.
That was month four. Right now, about fourteen months later, my running total across three platforms sits at Rs 1,21,860. Not a clean number, and that's the actual figure from my own tracking sheet, not something rounded for a headline.
How this even started
I was doing an unrelated science degree with genuinely no plan for after graduation. A friend sent me a video of someone explaining how they'd found a bug in a food delivery app's coupon system and gotten paid for it. I watched it twice, mostly confused, and made a Bugcrowd account that same night out of pure boredom.
The first week I felt unstoppable. I read every public writeup I could find. By the second week I realized I understood almost none of it.
The stretch where nothing worked
Nobody puts this part in their video. I submitted somewhere around 35 reports across my first four months. Most came back "Informative," meaning yes, technically a bug, but not severe enough for any payment. A handful were duplicates. Two got closed as "Not Applicable" because I hadn't actually read the scope document properly before testing.
One company added my name to their public Hall of Fame page. No cash attached to that listing, just a name on a webpage. At the time it felt like an insult dressed up as a reward. Looking back now it's almost funny.
There was a genuine low point where I told a friend I was done with the whole thing. I wasn't, obviously, since I'm writing this. But I meant it that night.
One real earning story like this every week, on WhatsApp.
Join FreeThe first payment: Rs 2,900
The first bug that actually paid was on a mid-sized SaaS company's support portal. Their password reset confirmation page reflected a URL parameter directly onto the screen without sanitizing it, a textbook reflected XSS.
I tested it by injecting a harmless script tag into the parameter and watching it execute in the browser. Took maybe twenty minutes to find, another hour to write up properly with screenshots and reproduction steps.
Five days later: "Valid. Low severity. Bounty approved: $35."
Thirty-five dollars came out to roughly Rs 2,900 at the time. Genuinely small money. But it was the first time the number in my bank statement had anything to do with hours I'd spent hunting instead of a college assignment, and that distinction mattered more than the amount did.
The one that actually moved the needle
Smaller bounties trickled in after that: Rs 1,800 here, Rs 4,500 there, nothing dramatic. The real shift came from a logistics company's internal dashboard, where I found that changing a single order ID in the API request let me pull up other customers' delivery addresses and phone numbers.
That's an IDOR, an insecure direct object reference, and it's one of the more common critical-severity findings because it's often simple to exploit once you spot the pattern.
I sat on that report for two days before submitting it, half convinced I was missing something and it wouldn't actually work the way I thought. It worked. The triage response took nine days this time. When it landed: "Confirmed. Critical severity. Bounty: $500."
Roughly Rs 41,000 on a single report. That one bug alone nearly doubled everything I'd earned up to that point combined.
Honestly, the bug itself wasn't technically impressive. It was one parameter, changed by one digit. What it taught me is that bug bounty rewards speed and thoroughness over cleverness. The researcher who finds the obvious thing first and documents it well usually beats the one hunting for something exotic.
What the actual week looks like now
I put in around five or six hours a week, mostly on weekends. I've since added a YesWeHack account for access to programs based in Europe, where I've noticed the pay tends to run slightly higher for equivalent severity.
The pattern I've settled into: newly launched programs get flooded with far fewer researchers in their first 48 hours than established ones. A company that's been running its program for two years already has thousands of hours of prior testing against it. A program that launched yesterday hasn't.
So I keep notifications on for new program launches and try to give those my first attention before they get crowded.
What I got wrong going in
I assumed this was "find bug, get paid," basically a treasure hunt. What it actually involves is reading scope documents closely, understanding which endpoints are fair game, and accepting that most weeks produce nothing usable at all.
The income swings hard too. One month brought Rs 28,000 from two mid-severity findings. The next two months brought close to zero, despite putting in similar hours. That inconsistency is exactly why I still treat this as a side project rather than something to depend on, alongside other freelance content writing work that pays more predictably even if the ceiling is lower.
I submitted another report last night, a possible IDOR on a fintech app's referral system, though I'm still not fully sure it holds up under scrutiny. No response yet. It might come back duplicate. It might come back critical. That uncertainty, weirdly, is still the part that keeps me opening the laptop.
Frequently Asked Questions
Do you need a computer science degree to start bug bounty hunting?▼
No. I was doing a BSc in a completely unrelated subject when I started. What you need is enough understanding of how websites talk to servers, which you can pick up from free resources, and a willingness to sit with a broken feature for hours without getting anything for it.
Which bug bounty platforms are worth joining first?▼
Bugcrowd and HackerOne are the two biggest and both are free to join. I'd start on Bugcrowd because their public programs tend to have clearer scope documents for beginners. YesWeHack is good once you want access to more European companies.
How much do individual bug bounties typically pay?▼
It varies enormously by severity and company. My smallest paid bounty was around Rs 2,900. My largest single one was close to Rs 41,000. Critical bugs on well-funded programs can go into lakhs, but those are rare and usually go to researchers with years of experience.
Is bug bounty hunting reliable as a main income source?▼
For me, no, not yet. Some months brought in Rs 28,000, other months brought in nothing at all. Most hunters I've talked to online treat it as a side income unless they've built a strong reputation over several years.
What's the biggest mistake new bug hunters make?▼
Testing outside the program's scope. Every program lists exactly what's allowed and what isn't, and I got a warning email once for poking at a subdomain that wasn't listed. Read the scope document twice before you touch anything.
Ram Ashare
Founder, Simple Kamai
Testing online earning methods in India since 2023 — freelancing, digital products, affiliate marketing, and more. Only writing about what has actually worked.
Learn more →Free: The First Earning Checklist (7-Day Action Plan)
Subscribe and get instant access to the 7-day checklist that takes you from "I'll start soon" to your first proposal sent. Plus one tested earning tip every week — no fluff.
Join WhatsApp Channel
Get weekly earning tips
Also Read
A Performance Marketer's Real Income: Getting Clients Through Meta Ads
I burned Rs 2,600 of my own money learning Meta Ads before landing a paying client. First retainer came 71 days later. Here's the honest version, mistakes included.
Learning Flutter for 6 Months: My First App Project Paid Rs 22,000
Six months of YouTube tutorials led to a Rs 19,500 app project for a local salon. It crashed the morning after launch. Here's the honest income breakdown of freelance Flutter development.
Ghostwriter: 3 Books Written, No Name on the Cover, Real Income
Three books written, zero author credit on any of them. First one paid Rs 34,000 and seeing a stranger's name on the Amazon listing felt stranger than expected. The honest math on ghostwriting.