Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Anthropic
Anthropic HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Anthropic? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical $5,800 avg 5 reports thin
High $3,384 avg 171 reports firm
Medium $909 avg 176 reports firm
Low $185 avg 73 reports firm

$1,059,485 paid to researchers in total, $292,500 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
5,478
in 90 days
Resolved
459
all time, last one yesterday
Participants
529
hunters engaged
Response efficiency
96%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 5,336–5,561
25 Aug 5,478 reports 22 Sep

Response targets it sets itself

First response
3 days
Triage
7 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 31 days (17 snapshots): intake up 180 reports; response efficiency down 1 points; 90-day payout down $36,950.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

508 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 ryotak 2,817 62 / 92 67%
2 stopwar 659 16 / 32 50%
3 liamconner10 642 4 / 17 24%
4 eran667 531 10 / 13 77%
5 amr_id 454 15 / 44 34%
6 edbr 345 8 / 10 80%
7 lucasfutures 308 13 / 75 17%
8 mahoraga007 291 3 / 47 6%
9 realmarmarlabs 278 11 / 45 24%
10 norwegianlamb 275 10 / 130 8%
11 orenyom 270 6 / 7 86%
12 anagnorisis2peripeteia 256 1 / 86 1%
13 philts 244 7 / 8 88%
14 cotu223 236 6 / 62 10%
14 fabiusartrel 236 4 / 5 80%
16 argareksapatii 233 7 / 27 26%
17 waynezinn 232 4 / 30 13%
18 yottt 214 8 / 43 19%
19 n9j3h9u8 196 8 / 14 57%
20 m0chan 190 8 / 11 73%
21 wunderwuzzi23 184 4 / 10 40%
22 suul 183 10 / 34 29%
23 lachlan2k 175 3 / 6 50%
24 cantina-security 174 5 / 40 13%
25 d0xing 173 6 / 8 75%

Showing the top 25 of 508 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Anthropic is an AI safety and research company that builds reliable, interpretable, and steerable AI systems.

Responsiveness
96% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
May 2026
Scope entries
23 HackerOne’s count

Scope

22 assets
AssetTypeEligibilityMax severity
anthropic.atlassian.com URL ✓ bounty Critical
API & SDKs AI MODEL ✓ bounty Critical
api.anthropic.com URL ✓ bounty Critical
Claude iOS app APPLE STORE APP ID ✓ bounty Critical
Claude Code OTHER ✓ bounty Critical
Show all 22 assets
AssetTypeEligibilityMax severity
Claude Desktop Extensions and Claude.ai MCP servers OTHER ✓ bounty Critical
Claude in Chrome OTHER ✓ bounty Critical
Claude Model Safety OTHER ✓ bounty Critical
claude.ai URL ✓ bounty Critical
console.anthropic.com URL ✓ bounty Critical
Core Assets OTHER ✓ bounty Critical
​Core Assets | OTHER ✓ bounty Critical
docs.anthropic.com URL ✓ bounty Critical
github.com/anthropics SOURCE CODE ✓ bounty Critical
https://apps.apple.com/us/app/claude/id6473753684 APPLE STORE APP ID ✓ bounty Critical
Infrastructure & Internal Apps/Services OTHER ✓ bounty Critical
Leaked Employee API Keys OTHER ✓ bounty Critical
Non-Core Assets OTHER ✓ bounty Critical
Official Clients OTHER ✓ bounty Critical
support.anthropic.com URL ✓ bounty Critical
github.com/modelcontextprotocol/servers-archived SOURCE CODE out None
https://github.com/modelcontextprotocol SOURCE CODE out None

HackerOne lists 23 scope entries; its public listing groups many assets under one label, so identical entries are shown once.