VYPR
advisoryPublished Aug 1, 2026· 1 source

HackerOne Mandates Identity Verification for Bug Bounty Submissions

HackerOne now requires government ID verification for all bug bounty submissions to comply with regulations, impacting hackers seeking rewards.

HackerOne has implemented a mandatory identity verification process for all researchers submitting bug bounty reports on its platform. This new policy, driven by regulatory compliance requirements, distinguishes bug bounty programs (BBPs) from vulnerability disclosure programs (VDPs), which will continue to be accessible to unverified individuals as they do not involve monetary rewards. Consequently, any hacker aiming to receive bounty payouts or participate in other reward-based programs must now complete this verification.

The verification process begins on the hacker's User profile page under the ID Verification header. Participants must first agree to HackerOne's Rules of Engagement, which outline additional terms for those granted increased internal access and credentials. Following this, they can initiate the verification through HackerOne's partner, Veriff. This involves capturing an image of a valid government-issued ID and, typically, a live selfie, which Veriff compares against the document.

HackerOne enforces strict environmental controls during verification. Researchers are prohibited from using VPNs, traffic anonymizers, jailbroken devices, SDK emulators, or Apple's private relay feature. Any attempt to use these tools will result in automatic rejection. Accepted forms of identification generally include passports, national ID cards, residence permits, and driver's licenses, though specific document types may vary by country. Only physical, undigitized copies are processed, as Veriff does not accept scanned or digital IDs.

Upon completion of the Veriff session, HackerOne usually sends a confirmation email within three business days. Pending reviews can take up to 48 hours before support should be contacted. This verification is not a one-time requirement; it must be renewed annually. Hackers are prompted to re-verify approximately one month before their existing credentials or ID documents expire. Failure to renew will result in the loss of access to verification-dependent programs and the removal of the hacker's verification badge.

It is important to note that this standard ID Verification is separate from HackerOne's more rigorous H1 Clear program, which includes a criminal background check and is reserved for a select group of vetted hackers. Even H1 Clear participants must complete their annual ID Verification to maintain their privileges.

Rejections are most commonly attributed to technical issues rather than concerns about identity fraud. Common reasons for failure include blurry text on the ID, unreadable machine-readable zones (MRZ), incomplete barcodes, expired documents, or the submission of photocopied IDs instead of live photographs. HackerOne advises users to ensure good lighting, remove glasses or headwear, and use supported browsers like Chrome or Safari to increase the likelihood of a successful verification session.

This regulatory-driven shift by HackerOne signifies an increasing trend of compliance expectations within the vulnerability disclosure and bug bounty ecosystem. Researchers who monetize their findings should plan their workflows to accommodate the verification and review timelines, which can range from 48 hours to three business days.

Synthesized by Vypr AI