# Security Bug Bounty Program Paused Due to Loss of Funding

DevFeed: [Security Bug Bounty Program Paused Due to Loss of Funding](<https://devfeed.tech/articles/security-bug-bounty-program-paused-due-to-loss-of-funding-2416.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties>)

Published: 2026-04-02T12:00:00Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [developers](<https://devfeed.tech/tags/developers.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Node.js has paused its security bug bounty program because the external funding source for monetary rewards was discontinued. Security reporting through HackerOne continues, but vulnerability reports are no longer eligible for bounty payouts.

## Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.