Shopify’s Bug Bounty Program: 2020 Review and What’s Next

Shopify’s Application Security team has released its annual review of the company’s bug bounty program, detailing record-breaking activity in 2020 and a slew of program changes for 2021. The year saw a sharp spike in report volume, major payout milestones, and a fundamental shift in how bounties are calculated.

A dashboard from the H1-2102 Live Hacking Event with HackerOne. On the left there are 3 circular images showing the top 3 hackers from the event. Underneath those images is each hacker's Reputation, Report, and Bounty numbers. is a table that shows the 4th to 7th place hackers and their Reputation, Report, and Bounty numbers. On the right hand side of the image is a logo of Shopify and below that logo is the total bounty paid of $274,676
H1-2102 Live Hacking Event Leaderboard

H1-2102: A Record-Breaking Virtual Event

Shopify ran its first Virtual Live Hacking Event, H1-2102, in collaboration with HackerOne. The event invited 38 researchers from seven countries to test areas previously outside the main program’s scope, including Plus organizations and Shopify Support Services. The event yielded 83 valid reports, with payouts exceeding $220,000 in bounties plus an additional $54,000 in bonuses. Top performers included @ngalog, @rhynorater, and @francisbeaudoin, whose findings are being disclosed through Shopify’s public hacktivity feed.

Bounty Milestones and a Critical Response

At the start of 2020, Shopify raised its maximum bounty to $50,000. The impact was immediate: just days after the increase, @ngalog filed multiple critical vulnerability reports against Shopify ID, the company’s single sign-on service. The public disclosure of that research proved valuable beyond the individual payouts—it spurred a wave of follow-on research, with report volume tripling in the month after the disclosures. Over the course of 2020, Shopify paid out more than $460,000 in bounties, pushing cumulative payouts across all its programs past the $2 million mark.

Moving to CVSS-Based Bounties

In October 2020, Shopify retired its fixed bounty table in favor of calculating payments using the Common Vulnerability Scoring System (CVSS). Originally planned as a month-long experiment, the approach was adopted permanently almost immediately. The new method provides greater transparency—Shopify shares the full metric breakdown behind each score—and the company has released its internal CVSS calculator publicly so researchers can assess the severity of their own findings before submitting. Internally, the change has made discussions about impact more objective and ensures payouts reflect real-world risk to merchants and their buyers.

GraphQL Hacking Guide

To reduce barriers for researchers, Shopify published a guide to hacking its GraphQL APIs in September 2020. The guide covers extracting the full GraphQL schema, including functionality available only in the unstable version, performing queries against the Admin API, and automatically detecting schema changes. Following its release, Shopify observed a noticeable uptick in reports targeting undocumented areas of the Admin API—an outcome the company sees as a win for both researchers and its own security posture.

What’s Changing in 2021

Fist Bump Over Desk

A Dedicated Bug Bounty Team

The spike in activity during 2020 led Shopify’s Application Security team to run monthly “bug squash” sprints, a move that proved so successful that the company now maintains a permanent team dedicated to the HackerOne program. The goal is faster response times and a lower duplicate rate. Shopify tracks duplicates as a key metric and aims to keep the monthly count below ten—down from a high of 38 during busy periods in 2020, before the squash initiative began. The dedicated team also frees up the broader Application Security group for other work throughout the year.

More Hacking Resources

Shopify continues to expand its Bug Bounty Resources repository on GitHub, which is designed to lower the learning curve for new researchers. Upcoming additions will include tips for testing apps that authenticate using session tokens. The company encourages researchers to watch the repository for updates and to send resource requests to [email protected].

Better Follow-Up on Reports

With record report volumes came a challenge: Shopify sometimes failed to respond to researcher questions on closed reports, a lapse it acknowledges fell short of its commitments. In response, the team is building internal tooling to surface reports that require follow-up. A dashboard filter now flags reports where the researcher last commented, making it easy to identify items awaiting a response.

Shopify Experiments, Version 2.0

Shopify is revamping its private Shopify Experiments program, which previously ran a series of tests aimed at improving the public program. The new version will focus on special apps and features that are not yet publicly available or practical to test on the main program. The company plans to run “mini events” throughout the year highlighting these targets, with additional promotions and bonuses attached. Invites for the relaunch will go out to researchers based on their report history from the past 12 months, with criteria evaluated monthly. Eligible researchers must have at least four bounty-eligible reports that are Triaged or Resolved, and no more than 25% of their submissions can be closed as Informative or Not Applicable on the main program. Participants must maintain the same signal-to-noise ratio on the Experiments program itself, with the roster reviewed quarterly to ensure all invitees remain active and meet the bar.

A dashboard that displays Shopify's solution to ensuring hackers questions are followed up.  The left hand side of the dashboard has a search box and options to filter the reports. Those filters are based on the bug bounty programs and the report states options.  In the report states section the Awaiting Response state is checked.  On the right hand side of the dashboard is a table that contains values for Report id, Report Title, Program, Reported by, Total Bounty, and Submitted.  The table shows 3 reports that are in a Report state of Resolved.
Shopify's Internal Dashboard that allows filtering by reports that require following up.

A Year of Record Volume

A bar chart showing the number of bug bounty reports submitted by year from 2015 - 2020. The chart shows the large increase in report in 2020 compared to the period 2016 - 2019
Number of Reports by Year - Number of Reports vs. Year

Report volume grew sharply in 2020: Shopify received 3,093 submissions, up from 1,379 the year before. April and September were the busiest months, each topping 400 reports, coinciding with public disclosures that drew fresh interest to the program.

A bar graph showing the number of bug bounty reports submitted by month for all of 2020. The chart shows April and Sept as months that saw a large increase in reports  submitted
Number of Reports by Month - Number of Reports vs. Month

April brought @ngalog's findings on the Shopify ID merge flow, and September saw @francisbeaudoin's email confirmation bypass. The company credits public disclosure with improving overall report quality: it gives researchers concrete examples to learn from and keeps attention on the program.

A bar chart showing the  bug bounty report states by year from 2015 - 2020. Each year is broken down by state in different colours (duplicate, informative, not-applicable, resolved, spam). The chart shows the increase in reports that are marked Informative and Not Applicable over the year to a high in 2020.
Report States by Year - Number of Reports vs. Year

The state distribution of reports also shifted. Informative and Not Applicable classifications rose disproportionately—over 300% and 80% respectively compared with 2019—despite no policy changes. Monthly data shows spikes around the key disclosures and a steady upward trajectory.

A line graph showing the  bug bounty report states by month for 2020. The graph is broken down by state in different colours (duplicate, informative, not-applicable, resolved, spam). The chart shows the increase in reports that are marked Informative and Not Applicable over the year. It also shows the spike in those reports in April and September.
Report States by Month - Number of Reports vs. Month

Shopify suggests the broader trend may tie to HackerOne's revisions to Signal calculations, which could have encouraged researchers to submit more speculative Informative reports. COVID-19 restrictions may also have played a part, with more researchers at home looking to supplement income through bounties.

A line graph showing Average Shopify Response Times in hours by year from 2015 to 2020. The graph is broken down by average time to bounty, average time to close hours, average time to first response, and average time to triage hours.

Despite the increased load, response times stayed close to 2019 levels. Average time to first response was 25 hours, up from 16. The team triaged 215 reports in 2020 versus 131 in 2019; triage time increased slightly from 2 days 13 hours to 3 days 11 hours. Time-to-bounty rose from 7 days 1 hour to 12 days 15 hours, largely due to the transition to CVSS-based scoring. The team now meets twice weekly to align on scores and has streamlined the process to bring that metric down.

Payouts roughly tripled: over $460,000 was awarded, compared to about $130,000 in 2019. The 50k maximum bounty introduced at the start of 2020 drove the average higher—$2,070 per bounty versus $1,139 previously.