Shopify Doubles Top Bug Bounty Payout to $100,000
Shopify’s Application Security team has announced updates to its bug bounty program for 2022, headlined by a doubling of the maximum payout. The changes follow a record 2021, during which the company paid out over $1 million in bounties—more than double the roughly $460,000 awarded in 2020. That figure includes two instances of the previous $50,000 maximum bounty for CVSS 10.0 issues, first awarded in January 2021 and again in December.
New Payout Scale and Core Asset Designations
Effective immediately, a report scoring CVSS 10.0 now earns $100,000. The increases apply specifically to the High and Critical severity brackets.
Alongside the payout increase, Shopify has moved several services into its highest severity tier, classifying them as Core assets. High and Critical vulnerabilities found in these services will be compensated according to the new scale. The newly designated Core assets are:
- shopify.plus
- arrive-server.shopifycloud.com
- shop.app
One caveat: issues specific to the mobile client itself will still be treated as Non-Core under the existing "Shopify Mobile Applications" category.
Scoring Transparency and Learning Resources
Shopify has published a CVSS scoring guide in its Bug Bounty Resources repository to address common questions about bounty decisions. The company says transparency around its scoring process is a priority and welcomes feedback from researchers. Additional resources for newcomers are planned for the repository, including guides and blog posts aimed at flattening the learning curve for those getting started with hacking on Shopify.
Inside the 2021 Numbers
The payout surge reflects several trends from last year. Researchers submitted over 3,000 reports across Shopify’s programs—volume on par with 2020, which was itself a large surge from prior years. Of those submissions, the average bounty in 2021 was approximately $3,000, up from roughly $2,070 in 2020.
Report quality improved as well: approximately 23% of incoming reports were valid issues, up from 19% in 2020. Meanwhile, "Not Applicable" findings dropped to 26.75% in 2021, down sharply from 41.92% the previous year. Shopify attributes both trends to clearer feedback, transparent CVSS scoring, and policy updates that help guide researchers toward more impactful work.
A Full Year of CVSS-Based Bounties
2021 marked the first complete year of bounties determined via the Common Vulnerability Scoring System. Shopify began using CVSS in fall 2020 and launched its own calculator to set bounty amounts. According to the team, the new system has led to more thorough internal discussions and more consistent decisions. Each bounty is scored by the full team, and the scoring metrics are shared with researchers alongside every payout. Follow-up conversations about specific metric decisions have been more productive as a result.
Supporting Open Source
In 2021, Shopify became a sponsor of the Internet Bug Bounty program to help fund bounties for open-source projects. The company also committed an additional $500 bonus for all valid issues in the Rails program that come with an accepted patch.
Response Times
Shopify tracks response times monthly and publishes updates via the @ShopifyEng Twitter account. Year-over-year figures show a slight increase in time to triage but a significant improvement in time to bounty: 137 hours in 2021, down from 249 in 2020. The team says it is actively working on automation through the HackerOne API to shorten response times further.




