档案库 · 开发与企业工具 · 战略决策 · 2012–2026
HackerOne的众包黑客赌注:融资1.6亿美元后,社区反了
HackerOne押注企业会为全球黑客群体的漏洞报告买单;在融资1.6亿美元后,它转向企业销售和AI,社区称信任已破裂。
HackerOne
做的是什么生意
San Francisco bug-bounty marketplace (founded 2012) connecting companies with a global community of ethical hackers who find and report vulnerabilities for cash bounties; later added pentesting, AI red teaming and continuous-exposure products.
启动资金:~$160M raised since founding in 2012, capped by a $49M Series E in Jan 2022 led by GP Bullhound with Benchmark, NEA, Dragoneer and Valor (per TechCrunch).
起因
In 2011, two ethical hackers, Jobert Abma and Michiel Prins, deliberately found vulnerabilities at 100 large tech companies to prove the model; HackerOne was founded in 2012 to make that kind of research legal, consensual and paid. It grew into the category leader in bug bounty, with customers like the US Department of Defense, Google, Dropbox, Microsoft and Twitter, and raised close to $160M through a $49M Series E in January 2022.
经过
Through the late 2010s, live hacking events and community programs made HackerOne the center of the ethical-hacking world. After the Series E, the company shifted toward enterprise sales: capacity-based fees and multi-year contracts, a sales organization, and repositioning as an AI-security vendor with the Hai copilot and later an agentic platform for 'continuous threat exposure management' (CTEM). In November 2024, longtime CEO Marten Mickos was replaced by Kara Sprague, F5's former chief product officer. In February 2026, researchers noticed ToS language that appeared to allow submissions to train AI models; founders denied training on researcher data and promised clearer terms, but a widely discussed August 2026 first-hand account argues the company had already automated parts of triage and review with AI, eroding the community's trust.
结果
Still live as of Sept 2, 2026: HackerOne operates its marketplace and CTEM platform under CEO Kara Sprague, with no shutdown or sale announced. The August 2026 HN-front-page account (388 points, 201 comments) describes a decade-long slide from hacker-first marketplace to sales-led vendor, and treats the February 2026 AI-training controversy as the breaking point of community trust.
背景
HackerOne成立于2012年,总部在旧金山,它押注企业会付费给全球白帽黑客群体来发现漏洞,并且一个给研究者提供法律许可、流程和现金奖励的平台能击败传统渗透测试公司。这一赌注见效了:客户包括美国国防部、谷歌、Dropbox、微软和Twitter,到2022年1月共融资近1.6亿美元,其中E轮为4900万美元。
这个市场真正的资产在供给端。现场黑客活动、社区项目和黑客优先的产品决策建立了一个研究者网络,能对目标发起密集的高质量报告攻击;TechCrunch报道称,某一年内发现了超过17000个高危或严重漏洞。大约在2020至2021年间,公司转向企业销售——容量费、多年合同、客户经理——后来在2024年11月起由前F5高管Kara Sprague主导,重金押注AI和持续威胁暴露管理。
2026年2月,研究者注意到服务条款似乎允许HackerOne用他们的提交内容训练AI。联合创始人Alex Rice和Sprague否认用研究者或客户数据训练生成式模型,并承诺澄清条款,但怀疑者指出公司自己的代理AI产品和自动化分类流程。2026年8月,一位资深研究者和项目经理发布第一人称文章,广为流传,指从黑客社区到销售主导的转变侵蚀了平台的核心信任。
这篇文章于2026年8月10日登上HN首页,获得388分和201条评论。截至2026年9月2日,HackerOne仍运营其市场和CTEM产品,但这件事引发一个悬念:当平台开始将群体当作数据和竞争对手对待,它还能留住这个被其变现的群体吗?
这件事要成立,得有什么
- 创始切入点——给研究者法律许可和现金——解决了一个真实的合规问题,并创造了一个真正的双边市场。
- 美国国防部、谷歌等客户给了市场制度性信誉,这是任何初创公司都无法买到的。
- 社区仪式(现场黑客活动、俱乐部、大使)是护城河,而文章指出这些是向企业转型时最先被砍掉的部分。
- 2026年2月的AI训练风波把战略漂移变成了信任断裂,因为平台的价值依赖于研究者相信他们的工作没有被用来对付自己。
可借鉴之处
市场平台的护城河在供给端:将忠诚度从创造价值的黑客转向企业合同和AI,社区一旦离去,护城河也就没了。
后续进展
截至2026年9月2日,HackerOne仍在运营,CEO是Kara Sprague(自2024年11月4日起),销售漏洞赏金、渗透测试、AI红队和CTEM平台。2026年2月的AI使用研究者提交物的争议,引来联合创始人Alex Rice和Sprague的公开否认,并承诺修订服务条款。2026年8月那篇HN首页长文(388分,201条评论)汇集了研究者多年来对自动化分类、平台停滞和企业转型的不满;截至asOf日期,未宣布反转或重大重组。
资料来源
- What Happened to HackerOne?
- Bug bounty giant HackerOne lands $49M, thanks to cloud adoption boon
- HackerOne Appoints Kara Sprague As CEO
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡