Trasser 0 Newbie Poster

I have a question for those who are looking for bugs and vulnerabilities for money. How are you looking for customers? Is it freelance or a permanent job or a hobby? I found one blockchain project that offers to find vulnerabilities for money. I will post the text of their proposal, if the administration does not mind:

In order to improve the security of the program code, we announce the beginning of bug-hunting.
Anyone who finds a new critical bug (vulnerability) will get 100 000
TERA.
Bug should be reported confidentially to progr76@gmail.com or telegram @progr76
TERA Foundation: https://terafoundation.org

What do you think of this?

RichardHarrris commented: hm...interesting.. +0

Dani AI

Generated

— short, practical guidance.

Many people bug‑hunt as a hobby/side income, some build a freelance pipeline, and a few do it full time (in-house or through security consultancies). The easiest ways to find paid work are: join managed bug‑bounty platforms for scale and safe‑harbor; respond to public disclosure programs; pitch audits directly to projects that have active code/repos; or join a firm that supplies audits. Platforms reduce client‑acquisition work; direct contracts pay more but require negotiation and paperwork.

Before touching any system, always vet the offer and get written authorization. For any direct bounty you find (especially small projects or token teams): confirm identity and team presence, ask for an explicit scope of testing, require a safe‑harbor/SOW or NDA, get clear payment terms (amount, currency, escrow, timeline, KYC), and agree a disclosure timeline. Red flags: huge promised payouts with no contract, requests to run destructive tests, refusal to provide written permission, or insistence you disclose before payment. If any of these appear, decline.

Email template to request authorization (copy, edit, send):

Subject: Request for written authorization and scope for security testing

Hello [Project Team],

I am a security researcher interested in responsible testing of [project name]. Before proceeding please provide written confirmation of:

- Authorized scope (domains, repos, APIs) and excluded assets/tests
- Safe‑harbor or signed SOW/NDA protecting good‑faith testing
- Payment terms (amounts, method, escrow, timeline, KYC)
- Point of contact for sensitive reports and expected response window

Once confirmed in writing I will follow coordinated disclosure and submit reproducible reports and remediation suggestions.

Regards,
[Your Name / contact]

If they will not provide written terms, walk away and focus on recognized programs or paid audits.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.