---
title: "Shopify’s Bug Bounty Program Raises Maximum Payout in 2022"
description: "Shopify’s Application Security team reports on its 2021 bug bounty results and announces program changes for 2022. Effective immediately, the maximum bounty for a CVSS 10.0 issue doubles from $50,000 to $100,000, with higher High and Critical brackets, while Shopify Plus, Shop, and Shop Pay services move into the Core asset category; mobile-client-specific issues remain Non-Core. The program received more than 3,000 reports, paid over $1 million in bounties and bonuses, and saw approximately 23% of reports judged valid, up from 19% in 2020. After its first full year using CVSS-based scoring, Shopify reports more consistent decisions and a reduction in average time to bounty from 249 hours to 137, while adding a CVSS guide, more resources, and further open-source support."
---

# Shopify’s Bug Bounty Program Raises Maximum Payout in 2022

[Shopify](https://yomu.fyi/company/shopify) · 2023-10-18 · Mar 22, 2022

**Type:** Announcement

## Summary

Shopify’s Application Security team reports on its 2021 bug bounty results and announces program changes for 2022. Effective immediately, the maximum bounty for a CVSS 10.0 issue doubles from $50,000 to $100,000, with higher High and Critical brackets, while Shopify Plus, Shop, and Shop Pay services move into the Core asset category; mobile-client-specific issues remain Non-Core. The program received more than 3,000 reports, paid over $1 million in bounties and bonuses, and saw approximately 23% of reports judged valid, up from 19% in 2020. After its first full year using CVSS-based scoring, Shopify reports more consistent decisions and a reduction in average time to bounty from 249 hours to 137, while adding a CVSS guide, more resources, and further open-source support.

## Context

Shopify describes 2021 as a busy year for its bug bounty program, with more than 3,000 reports and over $1 million paid in bounties and bonuses. The changes are intended to reward impactful security research, improve guidance for researchers, and support open-source security.

## Approach / What changed

The program doubles the maximum bounty for a CVSS 10.0 issue to $100,000, increases High and Critical payouts, and moves Shopify Plus, Shop, and Shop Pay services into the Core asset category. Shopify also adds a CVSS scoring guide and planned resources, sponsors open-source bounties, offers an additional $500 bonus for valid Rails issues with accepted patches, and is working on HackerOne API automation to reduce response times.

## Takeaways

- The maximum bounty rises from $50,000 to $100,000 for CVSS 10.0 issues, with increases to the High and Critical brackets.
- Approximately 23% of incoming reports were valid in 2021, compared with 19% in 2020, while Not Applicable reports fell from 41.92% to 26.75%.
- Average time to bounty decreased to 137 hours in 2021 from 249 hours in 2020, although time to triage increased slightly.

**Tags:** [Developer Experience](https://yomu.fyi/topic/developer-experience), [Monitoring](https://yomu.fyi/topic/monitoring), [Open Source](https://yomu.fyi/topic/open-source)

- Source: [Shopify](https://shopify.engineering/shopify-bug-bounty-program-maximum-payout-2022)
- Source URL: https://shopify.engineering/shopify-bug-bounty-program-maximum-payout-2022
- Ingested by Yomu: 2026-08-30T15:27:14.372Z

[Read original post](https://shopify.engineering/shopify-bug-bounty-program-maximum-payout-2022)
