Hacker News new | ask | show | jobs
by ineedasername 1412 days ago
That depends: it wouldn’t matter how much they pay in bounties if the bounty hunter is double dipping by reporting the bug & also exploiting it for sellable data. Not saying that’s what happened here though.
1 comments

I mean if you're offering much more money for the bounty than could be earned on the blackmarket the hacker probably won't want to take the risk of double dipping.
You'd be surprised, risk is worth it.

But, twitter still gets to find out and fix it before even more damage was done. Your dips don't have to be double they can be many.