Loading…
Shopify’s Bug Bounty Program Raises Maximum Payout in 2022
2023-10-18
- Source
- Shopify
- Published
- Added to Yomu
Summary
Shopify’s Application Security team reports on its 2021 bug bounty results and announces program changes for 2022. Effective immediately, the maximum bounty for a CVSS 10.0 issue doubles from $50,000 to $100,000, with higher High and Critical brackets, while Shopify Plus, Shop, and Shop Pay services move into the Core asset category; mobile-client-specific issues remain Non-Core. The program received more than 3,000 reports, paid over $1 million in bounties and bonuses, and saw approximately 23% of reports judged valid, up from 19% in 2020. After its first full year using CVSS-based scoring, Shopify reports more consistent decisions and a reduction in average time to bounty from 249 hours to 137, while adding a CVSS guide, more resources, and further open-source support.
Context
Shopify describes 2021 as a busy year for its bug bounty program, with more than 3,000 reports and over $1 million paid in bounties and bonuses. The changes are intended to reward impactful security research, improve guidance for researchers, and support open-source security.
Approach / What changed
The program doubles the maximum bounty for a CVSS 10.0 issue to $100,000, increases High and Critical payouts, and moves Shopify Plus, Shop, and Shop Pay services into the Core asset category. Shopify also adds a CVSS scoring guide and planned resources, sponsors open-source bounties, offers an additional $500 bonus for valid Rails issues with accepted patches, and is working on HackerOne API automation to reduce response times.
Takeaways
- The maximum bounty rises from $50,000 to $100,000 for CVSS 10.0 issues, with increases to the High and Critical brackets.
- Approximately 23% of incoming reports were valid in 2021, compared with 19% in 2020, while Not Applicable reports fell from 41.92% to 26.75%.
- Average time to bounty decreased to 137 hours in 2021 from 249 hours in 2020, although time to triage increased slightly.