A Verified Identity Now Comes Before Any Payout
HackerOne, one of the largest coordinated vulnerability disclosure platforms, has told researchers that identity verification will become mandatory for its paid programs. According to notifications sent to users and reported across the security press in early August 2026, the requirement takes effect on August 14, 2026. From that date, every researcher must complete verification before their submissions to Bug Bounty Programs (BBPs) qualify for a reward.
The checks run through the third-party vendor Veriff. Researchers must provide a valid, undamaged government-issued physical ID such as a passport, driver's license, national ID card, or residence permit, and in some cases a live selfie. Applicants must be at least 18 years old. Reviews typically complete within 48 hours, with final confirmation inside roughly three business days. Verification must be renewed every 12 months, and HackerOne says it will prompt researchers about a month before either the verification or the underlying document expires.
Crucially, the change applies to paid programs only. Vulnerability Disclosure Programs (VDPs), which accept good-faith reports without monetary rewards, remain open to unverified and anonymous submissions, preserving a low-friction channel for defenders who simply want to report a flaw.
Why HackerOne Is Tightening the Gate
HackerOne frames the policy around fraud reduction, platform integrity, and regulatory compliance tied to researcher payouts. But community and industry coverage connect the timing to a broader problem: a sharp rise in low-quality, AI-generated report spam. As agentic tooling has made it trivial to mass-produce plausible-looking vulnerability write-ups, triage queues have swelled and average submission-handling times have crept upward.
By binding every paid submission to a verified human identity, HackerOne aims to raise the cost of spamming programs at scale, help genuine reports move through validation faster, and ensure the professional reputation a researcher builds stays attached to a real, accountable person. For program owners, that promises cleaner queues; for skilled hunters, it promises less noise competing for triage attention.
What Researchers Should Do Before August 14
Active researchers should not wait until the deadline. Verification starts on the User Profile page under the ID Verification section, where you sign HackerOne's Rules of Engagement before launching the Veriff session. Have a valid physical document ready and complete the flow on a clean device: VPNs, traffic anonymizers, jailbroken phones, SDK emulators, and the iOS private-reply function can all trigger an automatic rejection.
Mark the 12-month renewal on your calendar and watch for HackerOne's advance notice so an expired document never silently blocks a payout. Teams running internal disclosure processes should note the VDP exemption and decide whether their public intake still fits an unverified channel.
CYBERSHIELDZONE