---
title: "Updates on Shopify's Bug Bounty Program 2021 - Shopify"
description: "Shopify’s 2021 bug bounty update reviews a busier 2020 program and outlines planned improvements for hackers and internal responders. Its first virtual live hacking event brought together 38 hackers from seven countries, generated 83 valid reports, and paid more than $220,000 in bounties plus $54,000 in bonuses. Shopify also raised its maximum bounty to $50,000, surpassed $2 million in total awards, replaced its bounty table with CVSS-based scoring and a public calculator, and published a GraphQL hacking guide. To handle volume, the Application Security team created a dedicated HackerOne team, built a dashboard for follow-up questions, and planned more resources and a revised private Experiments program. In 2020, Shopify triaged 215 reports, paid over $460,000, and reported an average first-response time of 25 hours, while average triage and bounty times increased."
---

# Updates on Shopify's Bug Bounty Program 2021 - Shopify

[Shopify](https://yomu.fyi/company/shopify) · 2023-10-18 · Mar 11, 2021

**Type:** Announcement

## Summary

Shopify’s 2021 bug bounty update reviews a busier 2020 program and outlines planned improvements for hackers and internal responders. Its first virtual live hacking event brought together 38 hackers from seven countries, generated 83 valid reports, and paid more than $220,000 in bounties plus $54,000 in bonuses. Shopify also raised its maximum bounty to $50,000, surpassed $2 million in total awards, replaced its bounty table with CVSS-based scoring and a public calculator, and published a GraphQL hacking guide. To handle volume, the Application Security team created a dedicated HackerOne team, built a dashboard for follow-up questions, and planned more resources and a revised private Experiments program. In 2020, Shopify triaged 215 reports, paid over $460,000, and reported an average first-response time of 25 hours, while average triage and bounty times increased.

## Context

The bug bounty program was busier than ever in 2020. Higher report volume increased duplicate reports and made it harder for the team to follow up on hacker questions, particularly on closed reports, while Shopify also sought to reduce barriers to testing and improve bounty consistency.

## Approach / What changed

Shopify increased its maximum bounty, adopted CVSS-based bounty calculations with a public calculator, published a GraphQL hacking guide and other resources, created a permanent team dedicated to its HackerOne program, and developed internal tooling to identify reports awaiting follow-up. It also planned a revised private Experiments program and additional testing guidance.

## Takeaways

- The CVSS experiment began in October 2020 as a month-long trial and was adopted immediately as Shopify’s primary bounty method after the company judged it successful.
- Shopify’s GraphQL guide covers retrieving the full schema, including unstable functionality, querying the Admin API, and automatically detecting schema changes; reports about undocumented Admin API areas increased afterward.
- Average time to first response rose from 16 hours in 2019 to 25 hours in 2020, while the average bounty rose from $1,139 to $2,070.

**Tags:** [GraphQL](https://yomu.fyi/topic/graphql), [Testing](https://yomu.fyi/topic/testing)

- Source: [Shopify](https://shopify.engineering/shopify-bug-bounty-updates-2021)
- Source URL: https://shopify.engineering/shopify-bug-bounty-updates-2021
- Ingested by Yomu: 2026-08-31T01:10:07.450Z

[Read original post](https://shopify.engineering/shopify-bug-bounty-updates-2021)
