# Bug Bounty Year in Review 2018

DevFeed: [Bug Bounty Year in Review 2018](<https://devfeed.tech/articles/bug-bounty-year-in-review-2018-1587.md>)

Original publisher: [Read original article](<https://shopify.engineering/shopify-bug-bounty-year-in-review-2018>)

Author: Peter Yaworski

Published: 2018-12-20T18:27:00Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Shopify](<https://devfeed.tech/topics/shopify.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [reports](<https://devfeed.tech/tags/reports.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Shopify's 2018 Bug Bounty year-in-review describes its security program, community of researchers, HackerOne partnership, live hacking event, and improved report triage. Average triage time fell from four days in 2017 to 10 hours in 2018 through a dedicated weekly triager and severity-based validation and escalation.

## Source excerpt

With 2018 coming to a close, we thought it a good opportunity to once again reflect on our Bug Bounty program. At Shopify, our bounty program complements our security strategy and allows us to leverage a community of thousands of researchers who help secure our platform and create a better Shopify user experience. This was the fifth year we operated a bug bounty program, the third on HackerOne and our most successful to date (you can read about last year's results here).