Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 155: 2025 Hacker Stats & 2026 Goals

·1 hr 32 min·5 clips
The hosts argue that bug bounty gives “the coolest job title ever,” full flexibility, and constant dopamine.
1. Critical Thinking - Bug Bounty Podcast Episode 155 focuses on 2025 hacker stats and 2026 goals for full-time bug bounty hunters. 2. Justin and Brandon host the conversation, and Brandon joins live after travel and sickness delays while both compare their year-end numbers and goals. 3. The episode asks what a full-time bug bounty year actually looks like when measured by bugs, impact, collaborations, and payouts. 4. Justin says 2025 was shaped by AI bug bounty growth, hack bots, live hacking events, and his first year as a co-host. 5. Brandon says December brought Christmas chaos, a sick week, and a rushed schedule, but he still wanted to join the recap. 6. Justin says bug bounty feels unusual because it mixes the title “ethical hacker,” flexible work, and the thrill of getting paid for reports. 7. The hosts contrast bug bounty with salary work and client acquisition, saying reporting bugs avoids sales-heavy pressure. 8. Justin says one of the most gutting moments of the year was a live hacking event where he achieved RCE on scope but got paid about $3,000. 9. He then says the next two days produced about six criticals at his home program, which shifted his mood back up. 10. The hosts frame the year as a cycle of very high highs and very low lows, especially around dupe-heavy periods. 11. Justin names Tokyo as a top memory because he roomed with other hackers, stayed in an Airbnb, and felt the energy of a live hacking event. 12. Brandon names Seattle as a turning point because he won his first award, got on a run of successful hacking, and flew home business class. 13. Justin says another major memory was a New Relic bug where he watched the token land and felt like the result came together in real time. 14. Justin says he landed 104 bugs in 2025 across HackerOne, Google, and Bugcrowd, and Brandon says he finished just over 160. 15. Brandon says his submissions “looks like a rainbow” because he reports across XSS, CSRF, cache poisoning, business logic, broken access control, IDOR, prompt injection, information disclosure, and SSRF. 16. Justin says his own mix leaned heavily on AI bugs, IDOR, SSRF, business logic, and some RCE and XSS bypass work. 17. The conversation also covers lifetime impact percentages, with Brandon citing 22.8% and Justin discussing around 22% to 25% depending on the time window. 18. The tone stays reflective and technical, but the pacing is casual, with both hosts interrupting each other and adding practical details about reports, bounties, and target selection. 19. People who like bug bounty strategy, stats, and hacker year reviews will get the most out of this episode. 20. People looking for a tight single-case story or minimal technical detail may skip it.

As heard by us

A blunt year end case for treating AI bugs as their own class of problem.

The segment turns a year end AI security discussion into a practical argument for judging AI bugs on their own terms. As the hosts close out 2025 and look ahead to 2026, they make a plain point: CVSS does not fit AI bugs very well, especially when the harm depends on heavy user…

Read the full review in PlayNext →

Why you'd press play

A year-end gut check on why AI bugs refuse old severity math.

Read the full recommendation in PlayNext →
Listen to the show on