AUGUST 16, 2026

The Bug Bounty Coverage Gap in the S&P 500

We cross-referenced HackerOne's public scope data against our S&P 500 attack-surface scans. Most companies with real, live risk have nowhere for a researcher to report it.

The Bug Bounty Coverage Gap in the S&P 500

We cross-referenced HackerOne's public scope data against our S&P 500 attack-surface scans. Most companies with real, live risk have nowhere for a researcher to report it.

NullBlocks Research — August 2026


If you're a bug-bounty hunter, the first question for any target isn't "is there a bug" — it's "does anyone actually pay for this bug, and where do I send it." We wanted a real answer for the S&P 500 as a whole, not a handful of anecdotes, so we matched our existing attack-surface scan data against HackerOne's public program directory and asked two questions: how much of the index actually runs a program, and does that coverage line up with where the real risk is.

Methodology, up front

We scanned all 541 companies currently tracked in our dataset (domrecon's subdomain enumeration, port/service probing, and dangling-subdomain/ takeover detection — 278,367 subdomains total) and matched each company's known domains against HackerOne's Hacker API (/v1/hackers/programs + per-program structured_scopes) — this is the same live H1 data any authenticated hacker account can pull. We only have HackerOne coverage in this pass — Bugcrowd and self-hosted security.txt-only programs are not yet in this dataset, so the real coverage number is a floor, not a ceiling. Confirmed dangling-subdomain findings are the confirmed=true subset only — CNAME records pointing at an unclaimed cloud resource, independently verified, not a heuristic guess.

1. Only 15 of 541 companies (2.8%) have any matched HackerOne scope

2,484 individual asset-scope matches exist across the index — but they concentrate almost entirely in a small cluster of companies that already run mature, well-known programs:

Company Bounty-eligible scope entries Program
Hilton Worldwide 952 Hilton
Airbnb 273 Airbnb
PayPal 262 PayPal
GitHub 210 GitHub, Omise
Uber 207 Uber
Booking Holdings 197 Booking.com
Stripe 129 Stripe
CrowdStrike 101 Crowdstrike
Wells Fargo 60 Wells Fargo Bounty
Marriott International 27 Marriott Bug Bounty
Goldman Sachs 25 Goldman Sachs
Amazon 25 Amazon Vulnerability Research Program
Starbucks 8 Starbucks
Adobe 7 Adobe
Netflix 1 Netflix

Of the matched scope, 2,361 entries (95%) are rated critical max severity — meaning where coverage exists, it's usually meaningful coverage, not a token low-severity-only program. The gap isn't program quality. It's program existence.

2. Real subdomain-takeover risk exists well outside that cluster

Separately from bounty coverage, our dangling-subdomain detector flags CNAME records pointing at cloud resources (Azure, Fastly, GitHub Pages, Shopify, WP Engine, and others) that appear unclaimed — a classic subdomain-takeover setup. Across the index: 61 confirmed, CRITICAL-severity dangling subdomains spread across 24 distinct companies (plus 2,664 additional unconfirmed HIGH-severity candidates we haven't independently verified yet — reported here for context, not counted in the headline number).

Health Care has the most confirmed findings of any sector: 5 companies, 21 individual findings — more than double the next sector.

3. The overlap: 23 of 24 companies with a confirmed takeover risk have zero matched bounty coverage

This is the finding that actually matters for a hunter deciding where to spend time. Cross-referencing the 24 companies with a confirmed dangling subdomain against the 15 companies with matched HackerOne scope: only one company appears in both lists. Twenty-three of the twenty-four companies sitting on a real, independently-confirmed subdomain-takeover-class exposure have no HackerOne program covering that asset today (Bugcrowd/self-hosted disclosure not yet checked in this pass, so treat this as "no H1 coverage found," not "definitively no path to disclose" — see the caveat below).

For a researcher, that's the practical takeaway: the highest-severity, easiest-to-verify class of finding in this dataset is concentrated almost entirely outside the companies you'd normally check first for a paying program.

An honest caveat

We are not saying these 23 companies have no responsible-disclosure path at all — we haven't yet checked Bugcrowd's directory or each domain's own /.well-known/security.txt in this pass (that's the next enrichment on our list). What we can say with confidence: they have no HackerOne program whose published scope includes the affected domain, which is the first place most hunters look. Treat "no H1 match" as "worth checking security.txt and Bugcrowd yourself before you report," not "definitely no reward path."

What this means if you hunt bug bounties

  1. Don't assume "big company = has a program." 2.8% coverage in this dataset says the opposite — most S&P 500 companies, including some with real, confirmed exposure, simply don't run one on HackerOne.
  2. Check security.txt and Bugcrowd before writing anything off — this pass only checked one platform; a program can exist that we haven't matched yet.
  3. If you find a subdomain-takeover-class issue and no program covers it, report it responsibly through whatever channel the company does publish (security.txt contact, a general security@ address) — an unpaid but responsible disclosure is still the right move, and it's also how some of these companies eventually stand up a program in the first place.
  4. Where a program does exist and covers a critical-severity scope (the 15-company list above), that's where the highest-confidence, highest-reward opportunity concentrates in this specific dataset.

Check your own footprint

Everything above came from the same free tool anyone can run right now: domrecon.com — enter a domain, get a plain-English risk grade, version-matched CVEs, full technology stack, and live subdomain inventory, including whether we've matched it to a known bug-bounty program. No signup required.

If you want the aggregate, cross-company view instead of one domain at a time — the kind of query that produced this report — that's what we built next: Graph Explorer, continuous scanning of the S&P 500's public attack surface as one interactive graph. See what's in it →


Data as of 2026-08-16, one point-in-time snapshot from our nightly HackerOne sync and confirmed dangling-subdomain detector — not continuous monitoring. Spot an error, or want the underlying query for a specific company? Reply — we read every message.

NullBlocks Systems — domrecon attack-surface intelligence.