A Closer Look at GitHub’s Top Bug Hunters

GitHub has spent the last decade building out its Security Bug Bounty Program, and as the platform now hosts over 100 million developers and 420 million repositories, the program remains a critical layer in keeping that ecosystem safe. A key part of the program’s success is its collaboration with external researchers. To wrap up Cybersecurity Awareness Month, GitHub’s bug bounty team sat down with @adrianoapj, one of its top contributors, who specializes in information disclosure vulnerabilities.

From CTFs to a Full-Time Hunting Habit

Before entering the bug bounty space, @adrianoapj was already working in tech. His entry point came through a Brazilian cybersecurity YouTube channel, which led him to capture-the-flag (CTF) exercises and Hacker101 videos—resources he credits with giving him the foundational knowledge to start hunting. The GitHub program was the first he ever tested, and it remains the one where he sends most of his reports.

What kept him motivated early on was the program’s approach to defense-in-depth bugs. His very first report to GitHub was low in severity, but the company rewarded it with a bonus anyway, acknowledging the effort. Today, his motivation comes from the intellectual challenge, seeing the real-world impact of his findings, and, of course, the bounties.

Finding Bugs Without Automation

When @adrianoapj isn’t hunting bugs, he works full-time as an infosec analyst. He keeps up with vulnerability trends by reading write-ups and public disclosures on HackerOne, and he regularly uses HackTheBox and HackTheBox Academy to learn new bug classes and sharpen his techniques.

His favorite class of bugs is information disclosure, because those findings often carry significant impact and can sometimes be surprisingly easy to spot. His methodology leans heavily on manual testing. He generally skips automated tools in favor of first choosing a specific feature or website to test. GitHub Stars was an early target—a newly launched project he suspected few others were probing. That bet paid off with multiple significant vulnerabilities.

His typical process looks like this:

  • Study the chosen feature or project thoroughly
  • Brainstorm possible entry points or assumptions about where bugs might live
  • Test those hypotheses manually
  • Iterate or develop new tests until something surfaces

He also keeps a close eye on the GitHub Changelog to target new features and changes, which he considers fertile ground for finding fresh bugs.

Advice for Aspiring Researchers

For those starting out, @adrianoapj stresses that perseverance is non-negotiable. Bug hunting can be frustrating, especially with duplicate reports and dead-end rabbit holes, but he notes that every service is subject to bugs—the trick is keeping at it.

His recommended starting points:

  • Hacker101 for newcomers to cybersecurity and bug bounty
  • HackTheBox and HackTheBox Academy for improving skills and testing offensive security knowledge
  • Write-ups, blog posts, and public HackerOne reports from other researchers

You can find @adrianoapj on GitHub at adrianoapj and on LinkedIn at /in/adrianoapj.

GitHub continues to invite researchers to submit findings through HackerOne, and the company is actively looking to deepen its engagement with the security research community as it moves past the program’s 10-year milestone.