Dropbox Expands Bug Bounty Payouts and Researcher Rewards

Dropbox has announced a set of updates to its bug bounty program, which has been running since 2014. The company originally offered around $5,000 for critical bugs; that figure has now grown to more than triple the previous top bounty. The program has also added bonus awards for standout research, a VIP tier for trusted researchers, and matching donations for bounties donated to charity.

The company shared statistics on how it has performed since the program's launch. Measured over the full three-year period, 75% of responses to researchers came within two days and two hours, with the fastest response at roughly 50 minutes. Over the last 12 months, that 75th percentile response time has dropped to under 16 hours. For reports that are clearly high quality, payment is often issued immediately upon reproduction, sometimes within minutes of submission.

Fastest triage payout tweet
Fast triage payout acknowledgement

Faster Resolutions and a VIP Program

Beyond faster response times, Dropbox has focused on closing out reported bugs quickly. For reports earning bounties above $1,000, more than half were fixed and shipped within 16 days. Some bugs have been resolved in under an hour of initial disclosure.

The company has also formalized a VIP program for researchers who consistently submit high-quality work. VIP participants get early access to upcoming features. Since the VIP program began, 75% of reports from its participants have received a response within 16 hours; over the last year, that figure has been reduced to 9 hours.

Fast bugfix response acknowledgement from Frans Rosen

Bounties Tripled

The headline change is that bounties have been more than tripled. Critical bugs—such as those enabling remote code execution (RCE) on Dropbox servers—now top out at $32,768. RCE vulnerabilities affecting Dropbox's desktop or mobile clients carry bounties up to $18,564.

To recognize recent work under the old payout structure, Dropbox has topped up any high or critical reports submitted in the last six months with the equivalent increased bounty. That retroactive adjustment has resulted in an additional payout of over $28,000 for qualifying reports from this year.

Bonuses for Novel Research

Dropbox has also introduced a formal review process for particularly novel or high-quality submissions. At least twice a year, the security team will evaluate reports based on the quality of the research, the clarity of the write-up, and the level of engagement with the researcher, and award additional bonuses. The first round of these bonuses has already been distributed, adding $14,000 to researchers' earnings.

Some examples of the work that earned these bonuses include:

  • A local file disclosure vulnerability in ffmpeg HLS processing, reported by Neex. The impact was minimal because Dropbox sandboxes all video processing, but the submission stood out for its advanced vector: a video file that reads file contents.
  • An XSS issue in an outbound chat vendor used on Dropbox's marketing pages, reported by Mdv. Although the XSS existed on the vendor's domain, Dropbox pays based on impact rather than fault, and the report was praised for its quality and clear explanation of the risk to customers.
  • A mailgun misconfiguration on email.gateway.dropbox.com, reported by Frans. The domain was unused, so impact was low, but the bug was fixed within half an hour, and the report was recognized for its clear impact description and the innovative angle of investigating integration issues.

Donation Matching

Finally, Dropbox has begun matching bounty donations that researchers make to charity through HackerOne. The company has already matched a donation to Doctors Without Borders.