HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs).
The update, effective immediately, aims to strengthen platform integrity and meet regulatory compliance requirements for reward payments. Under the new policy, hackers must verify their identity before becoming eligible for any bounty payments.
Vulnerability Disclosure Programs (VDPs) remain unaffected and continue to accept public submissions without requiring ID verification, preserving open access for researchers who report vulnerabilities without seeking financial rewards.
HackerOne Mandates ID Verification
The verification process is powered by Veriff, a third-party identity verification vendor. HackerOne says reviews typically take up to 48 hours, though final confirmation can take up to three business days after the Veriff session concludes.
Hackers initiate verification on their profile page by clicking the ID Verification header and must first sign HackerOne’s Rules of Engagement before proceeding.
Once signed, users are redirected to Veriff to submit a government-issued ID, such as a passport, driver’s license, or residence permit, and, in some cases, a live selfie. Several restrictions apply throughout the process.
Applicants cannot use VPNs, traffic anonymizers, SDK emulators, or jailbroken devices, and iOS users are barred from using the private relay function.
Only physical, unexpired ID documents are accepted; digital copies and photocopies will be rejected, and applicants must be at least 18 years old.
Successful applicants receive a green verification badge on their profile, distinct from the more rigorous H1 Clear badge, which involves an additional criminal background check.
ID Verification isn’t a one-time process. Hackers must renew annually, with HackerOne prompting re-verification one month before the expiration of either the verification itself or the submitted ID documents, whichever comes first.
Failure to renew within this window results in immediate loss of ID-verified privileges, removal of the green badge, and loss of access to programs requiring verification.
Hackers enrolled in the H1 Clear program face the same renewal urgency, since Clear status depends on maintaining current ID verification. HackerOne outlined several common reasons for rejected applications.
These include expired IDs, photocopied documents, unreadable machine-readable zones (MRZ), blurry or cut-off barcode scans, and incorrect head positioning during the selfie step.
Applicants who fail twice in a row must contact HackerOne support directly for a new verification link, as Veriff will not disclose rejection reasons or verification status to users for confidentiality.
For the bug bounty ecosystem, this shift signals a broader industry move toward accountability and regulatory alignment, particularly as platforms that handle financial rewards face increasing scrutiny over anti-fraud and know-your-customer (KYC) obligations.
While VDP researchers retain frictionless access, the change effectively creates a two-tier system: open disclosure for public good, and verified identity for monetized vulnerability research.
Security researchers actively participating in HackerOne’s BBPs should prioritize completing verification promptly to avoid disruption to active bounty eligibility, especially those maintaining Clear status.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

