The Entire HackerOne Team is Beyond Excited that The Ranks of Seven-Figure-Earning Hackers have Risen to Eight This Month

By : Krishna Anindyo | Thursday, February 27 2020 - 13:40 IWST

Congratulations, Cosmin! The world's seventh million-dollar bug bounty hacker
Congratulations, Cosmin! The world's seventh million-dollar bug bounty hacker - Cosmin @inhibitor181 is the seventh to join this talented group of hackers, proving to the world that the concept of hacking as a viable career has become a reality. Not only are more hackers earning most or all of their income from hacking, but they’re also making a good living doing it.

Besides the eight hackers passing the US$1 million earnings milestone, twelve more hit US$500,000 in lifetime earnings and 146 earned US$100,000, up from 50 last year. That puts a hacking career well above today’s global average IT salary of US$89,732. 

We sat down with Cosmin to learn how he got started, what contributed to his success, and his views on the industry’s present and future. Congratulations, Cosmin.

Hey! My name is Cosmin and my hacker handle is inhibitor181. I am 30 years old, I was born and raised in Romania, Bucharest and have been living with my wife and 2 dogs in Germany for the past 6 years.

Totally by accident; it’s kind of a funny story. While working as a dev, we were allowed to pick for our future development an event or course. I, with a few colleagues, picked a practical hacking seminar in Hamburg and there I found out about the existence of bug bounty platforms.

Quickly enough, I have made an account, was miserable at first, but slowly, slowly gained more experience and now I have been doing it full-time for almost 2 years.

I usually work while my wife works and she has a different schedule. Let’s say I wake up, have breakfast, start hacking, I take my dogs out for a nice break and then I come back to continue hacking if I am still in the mood. If I am not in the mood or tired, I do something else, usually end up playing rocket league with some friends.

There are quite a few factors here and the combination is what it’s important for me, The steep learning curve and never-ending process of learning, The financial winnings, The live events I have a very competitive nature, In the end, I really love spending my time hacking and I enjoy trying to break other people’s work to make it better for the future for everybody.

Yes, I have a favourite program, a private one that usually eats about 70-80% of my time. Basically, if I am not going to a live hacking event I usually hack there. I really like very deep apps where you can learn from failures and from everything you do or read. When the pieces of the puzzle start coming together it’s very enjoyable and fulfilling.  


My favorite program had a 4x promo for criticals for just 24 hours with another 48 hours notice beforehand and I was in the middle of a breakthrough and research I was already doing for the last week. It was very lucky and I had managed to get 3 criticals in, gaining 3 x US$28k.

Very hard to say as each project is unique, has its own specific challenges and it’s shifting very often. I have various projects that I cannot make myself stick to, start or finish them. So with the risk of sounding extremely broad, those are the ones that are the most challenging, the ones that you cannot even start.

Industries that handle PII and financial institutions. In my opinion, those 2 are the critical parts in the online industry that has to be as secure as possible.

This is my daily job, we spend it on everything we want. We do not have any exquisite hobbies or anything that eats a big chunk of the money we have.

In my opinion identity theft is the biggest risk. Almost there is also the risk of losing your life savings or money. When one of those things happens, in order to “fix it”, if possible, you will need to spend incredible amounts of energy and time that will definitely affect you financially, mentally and physically.

Definitely, businesses both big and small seem to be a lot more open to hacker-powered security and start seeing its advantages. They are also more willing to invest more time and money into them in order to attract more experienced hackers and gain the maximum from it.

First, to realise that this takes time, it’s an incredibly steep learning curve! Then, be prepared to invest time into it. If you have those 2 in mind and you go down this path, you will definitely succeed.

Read the documentation, learn to write your own tools, read security articles, invest time also in research, learn to write your reports and always approach your target tactically and with the strategy that fits you well. Also, it’s very important to realise that you and your mindset are unique, so don’t follow what X or Y says. Try to grab from everybody little bits, analyse them and then integrate them in your workflow only if it suits you.




News Comment

Today's Industry

World Bank Group (Images by ITU)

Kamis, 05 Maret 2020 - 07:23 WIB

World Bank Group Announces Up to $12 Billion Immediate Support for Covid-19 Country Response

As Covid-19 reaches more than 60 countries, the World Bank Group is making available an initial package of up to $12 billion in immediate support to assist countries coping with the health and…

Association of International Certified Professional Accountants (Images by Irish Times Executive Jobs)

Rabu, 26 Februari 2020 - 12:48 WIB

Global Accounting Leaders Call on Profession to Help Address Climate Change

As part of The Prince’s Accounting for Sustainability Project (A4S) Accounting Bodies Network, which collectively represents over 2.5 million accountants and students worldwide, 14 major accounting…

HackerOne (Images by Tekno

Selasa, 25 Februari 2020 - 16:00 WIB

Hacking as a Career Soars in Popularity According to HackerOne’s 2020 Hacker Report

HackerOne, hacker-powered pen-test & bug bounty platform, today announced findings from the 2020 Hacker Report, which reveals that the concept of hacking as a viable career has become a reality,…

Google Play Store (Images by Brands of the World)

Selasa, 25 Februari 2020 - 13:05 WIB

Is the Google Play Store Safe? Not Yet.

Over recent years, there has been a lot of activity on Google’s part to improve the security of its Google Play app store. Why? Because millions of users have inadvertently downloaded thousands…

Cyber Attack (Images by IDN Times Jabar)

Jumat, 21 Februari 2020 - 09:09 WIB

Cyber Attack Fears are Delaying Business Innovation

Survey conducted by bug bounty and pentesting platform, HackerOne, has revealed that IT projects are being stifled due to security concerns. More than 80% of UK CISOs and CTOs who were interviewed…