# 2017 Bug Bounty Year in Review

DevFeed: [2017 Bug Bounty Year in Review](<https://devfeed.tech/articles/2017-bug-bounty-year-in-review-1311.md>)

Original publisher: [Read original article](<https://shopify.engineering/bug-bounty-year-in-review>)

Author: Peter Yaworski

Published: 2018-02-22T16:00:00Z

Content type: news

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [svg](<https://devfeed.tech/tags/svg.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [year-in-review](<https://devfeed.tech/tags/year-in-review.md>)

## AI overview

Shopify reviews its 2017 bug bounty program, including reported access-control, race-condition, and XSS issues, payouts, and results from the H1-415 hacking event.

## Source excerpt

7 minute read At Shopify, our bounty program complements our security strategy and allows us to leverage a community of thousands of researchers who help secure our platform and create a better Shopify user experience. We first launched the program in 2013 and moved to the HackerOne platform in 2015 to increase hacker awareness. Since then, we've continued to see increasing value in the reports submitted, and 2017 was no exception.