EN
Back to the archive

The archive · Developer & Business Tools · Strategic decision · 2012–2026

HackerOne's crowd-hacker bet: $160M raised, then the community revolted

HackerOne bet companies would pay a global hacker crowd for bugs; after $160M it shifted to enterprise sales and AI, and the community says trust broke.

HackerOne

The betThat the marketplace could grow into an enterprise security vendor - selling contracts, AI red teaming and CTEM - without losing the researchers who supply its value.Live

What the business is

San Francisco bug-bounty marketplace (founded 2012) connecting companies with a global community of ethical hackers who find and report vulnerabilities for cash bounties; later added pentesting, AI red teaming and continuous-exposure products.

Starting capital~$160M raised since founding in 2012, capped by a $49M Series E in Jan 2022 led by GP Bullhound with Benchmark, NEA, Dragoneer and Valor (per TechCrunch).

How it started

In 2011, two ethical hackers, Jobert Abma and Michiel Prins, deliberately found vulnerabilities at 100 large tech companies to prove the model; HackerOne was founded in 2012 to make that kind of research legal, consensual and paid. It grew into the category leader in bug bounty, with customers like the US Department of Defense, Google, Dropbox, Microsoft and Twitter, and raised close to $160M through a $49M Series E in January 2022.

What happened

Through the late 2010s, live hacking events and community programs made HackerOne the center of the ethical-hacking world. After the Series E, the company shifted toward enterprise sales: capacity-based fees and multi-year contracts, a sales organization, and repositioning as an AI-security vendor with the Hai copilot and later an agentic platform for 'continuous threat exposure management' (CTEM). In November 2024, longtime CEO Marten Mickos was replaced by Kara Sprague, F5's former chief product officer. In February 2026, researchers noticed ToS language that appeared to allow submissions to train AI models; founders denied training on researcher data and promised clearer terms, but a widely discussed August 2026 first-hand account argues the company had already automated parts of triage and review with AI, eroding the community's trust.

How it ended up

Still live as of Sept 2, 2026: HackerOne operates its marketplace and CTEM platform under CEO Kara Sprague, with no shutdown or sale announced. The August 2026 HN-front-page account (388 points, 201 comments) describes a decade-long slide from hacker-first marketplace to sales-led vendor, and treats the February 2026 AI-training controversy as the breaking point of community trust.

Background

HackerOne, founded in 2012 in San Francisco, bet that companies would pay a global crowd of ethical hackers to find vulnerabilities - and that a platform giving researchers legal consent, process and cash could beat the pentest firms. The bet worked: customers came to include the US Department of Defense, Google, Dropbox, Microsoft and Twitter, and the company raised close to $160M through a $49M Series E in January 2022.

The marketplace's real asset was its supply side. Live hacking events, community programs and hacker-first product decisions built a researcher network that could flood a target with high-quality reports; TechCrunch reported 17,000+ high or critical findings in a single year. Around 2020-2021, the company shifted toward enterprise sales - capacity fees, multi-year contracts, account managers - and later repositioned around AI and continuous threat exposure management, led from November 2024 by ex-F5 executive Kara Sprague.

In February 2026, researchers noticed terms that appeared to allow HackerOne to train AI on their submissions. Co-founder Alex Rice and Sprague denied training generative models on researcher or customer data and promised clarified terms, but skeptics pointed to the company's own agentic AI products and automated triage. A widely shared August 2026 first-hand account by a longtime researcher and program manager argues the shift from hacker community to sales-led vendor eroded the platform's core trust.

The account hit the HN front page on August 10, 2026 with 388 points and 201 comments. As of September 2, 2026, HackerOne still operates its marketplace and CTEM products, but the episode frames its open question: can a marketplace that monetizes its crowd keep that crowd when it starts treating the crowd as data and competitors?

What has to be true

  • The founding wedge - legal consent and cash for researchers - solved a real liability problem and created a genuine two-sided market.
  • Customers like the US DoD and Google gave the marketplace institutional credibility no startup could buy.
  • Community rituals (live hacking events, clubs, ambassadors) were the moat, and the account argues they were the first thing cut in the enterprise pivot.
  • The February 2026 AI-training scare turned a strategic drift into a trust rupture, because the platform's value depends on researchers believing their work is not being mined against them.

What can be applied

A marketplace's supply side is its moat: shift loyalty from the hackers who produce the value to enterprise contracts and AI, and the community can leave - taking the moat with it.

Aftermath

As of Sept 2, 2026, HackerOne remains live under CEO Kara Sprague (since Nov 4, 2024), selling bug bounty, pentesting, AI red teaming and its CTEM platform. The February 2026 controversy over AI use of researcher submissions drew public denials from co-founder Alex Rice and Sprague plus a promised ToS clarification. The August 2026 HN-front-page retrospective (388 points, 201 comments) consolidated years of researcher grievances about triage, platform stagnation and the enterprise pivot; no reversal or major restructuring had been announced by the asOf date.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases