Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Brave Software
Brave Software HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Brave Software? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical amount not published 20 reports
High $1,028 avg 89 reports firm
Medium $244 avg 192 reports firm
Low $100 avg 194 reports firm

$140,000 paid to researchers in total, $20,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
231
in 90 days
Resolved
524
all time, last one yesterday
Participants
349
hunters engaged
Response efficiency
100%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 209–233
25 Aug 231 reports 22 Sep

Response targets it sets itself

First response
3 days
Triage
9 days
Bounty
24 days
Resolution
260 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 31 days (17 snapshots): 90-day payout up $5,000.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

354 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 newfunction 1,733 59 / 80 74%
2 nishimunea 900 25 / 29 86%
3 metnew 428 15 / 18 83%
4 b4dc4t 334 13 / 32 41%
5 syarif07 327 13 / 52 25%
6 neeythann 293 9 / 11 82%
7 z3phyrus 224 9 / 19 47%
8 yilmazcanyigit 201 8 / 19 42%
9 kkarfalcon 191 11 / 19 58%
10 kmodi 190 5 / 13 38%
11 frozzipies 187 7 / 43 16%
12 0xbarq 169 7 / 13 54%
13 dogeshark 167 6 / 34 18%
14 renwa 165 5 / 10 50%
15 severusstalin 164 8 / 27 30%
16 0x999 161 3 / 4 75%
17 qab 155 5 / 8 63%
18 sheikhrishad0 154 8 / 14 57%
19 wester0x01 117 6 / 7 86%
20 shinchan_69 116 2 / 5 40%
21 masatokinugawa 114 2 / 3 67%
22 remonsec 105 5 / 8 63%
23 abdulsomedsadat 101 3 / 9 33%
23 ericlaw 101 3 / 5 60%
25 0xc4gr1 89 2 / 5 40%

Showing the top 25 of 354 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Responsiveness
100% HackerOne’s figure
Swag
Offered
Currency
USD
Submissions
Open
Launched
Oct 2016
Scope entries
47 HackerOne’s count

Scope

42 assets
AssetTypeEligibilityMax severity
0x0d8775f648430679a709e98d2b0cb6250d2887ef OTHER ✓ bounty Critical
0x44fcfabfbe32024a01b778c025d70498382cced0 OTHER ✓ bounty Critical
0x67fa2c06c9c6d4332f330e14a66bdf1873ef3d2b OTHER ✓ bounty Critical
0x7c31560552170ce96c4a7b018e93cddc19dc61b6 OTHER ✓ bounty Critical
0xfbfa258b9028c7d4fc52ce28031469214d10daeb OTHER ✓ bounty Critical
Show all 42 assets
AssetTypeEligibilityMax severity
account.brave.com URL ✓ bounty Critical
api-dashboard.search.brave.com URL ✓ bounty Critical
basicattentiontoken.org URL ✓ bounty Critical
Brave Browser Desktop DOWNLOADABLE EXECUTABLES ✓ bounty Critical
Brave websites OTHER ✓ bounty Critical
brave.com URL ✓ bounty Critical
com.brave.browser GOOGLE PLAY APP ID ✓ bounty Critical
com.brave.browser_beta GOOGLE PLAY APP ID ✓ bounty Critical
com.brave.ios.browser APPLE STORE APP ID ✓ bounty Critical
creators.basicattentiontoken.org URL ✓ bounty Critical
https://github.com/brave-intl/bat-balance SOURCE CODE ✓ bounty Critical
https://github.com/brave-intl/bat-client SOURCE CODE ✓ bounty Critical
https://github.com/brave-intl/bat-go SOURCE CODE ✓ bounty Critical
https://github.com/brave-intl/bat-ledger SOURCE CODE ✓ bounty Critical
https://github.com/brave-intl/bat-publisher DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://github.com/brave-intl/publishers DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://github.com/brave/*, https://github.com/brave-intl/* SOURCE CODE ✓ bounty Critical
https://github.com/brave/brave-core SOURCE CODE ✓ bounty Critical
https://github.com/brave/browser-ios URL ✓ bounty Critical
https://github.com/brave/vault-updater SOURCE CODE ✓ bounty Critical
https://laptop-updates.brave.com/latest/debian64 URL ✓ bounty Critical
https://laptop-updates.brave.com/latest/dev/debian64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/dev/ubuntu64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/fedora64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/linux64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/mint64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/openSUSE64 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/osx URL ✓ bounty Critical
https://laptop-updates.brave.com/latest/winia32 DOWNLOADABLE EXECUTABLES ✓ bounty Critical
https://laptop-updates.brave.com/latest/winx64 URL ✓ bounty Critical
search.brave.com URL ✓ bounty Critical
talk.brave.com URL ✓ bounty Critical
com.linkbubble.playstore GOOGLE PLAY APP ID out None
https://github.com/brave/brave-ios SOURCE CODE out None
https://github.com/brave/browser-laptop SOURCE CODE out None
https://github.com/brave/link-bubble SOURCE CODE out None
https://github.com/brave/muon SOURCE CODE out None

HackerOne lists 47 scope entries; its public listing groups many assets under one label, so identical entries are shown once.