Shopify’s Bug Bounty Program: 2020 Review and What’s Next
Shopify’s Application Security team has released its annual review of the company’s bug bounty program, detailing record-breaking activity in 2020 and a slew of program changes for 2021. The year saw a sharp spike in report volume, major payout milestones, and a fundamental shift in how bounties are calculated.
H1-2102: A Record-Breaking Virtual Event
Shopify ran its first Virtual Live Hacking Event, H1-2102, in collaboration with HackerOne. The event invited 38 researchers from seven countries to test areas previously outside the main program’s scope, including Plus organizations and Shopify Support Services. The event yielded 83 valid reports, with payouts exceeding $220,000 in bounties plus an additional $54,000 in bonuses. Top performers included @ngalog, @rhynorater, and @francisbeaudoin, whose findings are being disclosed through Shopify’s public hacktivity feed.
Bounty Milestones and a Critical Response
At the start of 2020, Shopify raised its maximum bounty to $50,000. The impact was immediate: just days after the increase, @ngalog filed multiple critical vulnerability reports against Shopify ID, the company’s single sign-on service. The public disclosure of that research proved valuable beyond the individual payouts—it spurred a wave of follow-on research, with report volume tripling in the month after the disclosures. Over the course of 2020, Shopify paid out more than $460,000 in bounties, pushing cumulative payouts across all its programs past the $2 million mark.
Moving to CVSS-Based Bounties
In October 2020, Shopify retired its fixed bounty table in favor of calculating payments using the Common Vulnerability Scoring System (CVSS). Originally planned as a month-long experiment, the approach was adopted permanently almost immediately. The new method provides greater transparency—Shopify shares the full metric breakdown behind each score—and the company has released its internal CVSS calculator publicly so researchers can assess the severity of their own findings before submitting. Internally, the change has made discussions about impact more objective and ensures payouts reflect real-world risk to merchants and their buyers.
GraphQL Hacking Guide
To reduce barriers for researchers, Shopify published a guide to hacking its GraphQL APIs in September 2020. The guide covers extracting the full GraphQL schema, including functionality available only in the unstable version, performing queries against the Admin API, and automatically detecting schema changes. Following its release, Shopify observed a noticeable uptick in reports targeting undocumented areas of the Admin API—an outcome the company sees as a win for both researchers and its own security posture.
What’s Changing in 2021
A Dedicated Bug Bounty Team
The spike in activity during 2020 led Shopify’s Application Security team to run monthly “bug squash” sprints, a move that proved so successful that the company now maintains a permanent team dedicated to the HackerOne program. The goal is faster response times and a lower duplicate rate. Shopify tracks duplicates as a key metric and aims to keep the monthly count below ten—down from a high of 38 during busy periods in 2020, before the squash initiative began. The dedicated team also frees up the broader Application Security group for other work throughout the year.
More Hacking Resources
Shopify continues to expand its Bug Bounty Resources repository on GitHub, which is designed to lower the learning curve for new researchers. Upcoming additions will include tips for testing apps that authenticate using session tokens. The company encourages researchers to watch the repository for updates and to send resource requests to [email protected].
Better Follow-Up on Reports
With record report volumes came a challenge: Shopify sometimes failed to respond to researcher questions on closed reports, a lapse it acknowledges fell short of its commitments. In response, the team is building internal tooling to surface reports that require follow-up. A dashboard filter now flags reports where the researcher last commented, making it easy to identify items awaiting a response.
Shopify Experiments, Version 2.0
Shopify is revamping its private Shopify Experiments program, which previously ran a series of tests aimed at improving the public program. The new version will focus on special apps and features that are not yet publicly available or practical to test on the main program. The company plans to run “mini events” throughout the year highlighting these targets, with additional promotions and bonuses attached. Invites for the relaunch will go out to researchers based on their report history from the past 12 months, with criteria evaluated monthly. Eligible researchers must have at least four bounty-eligible reports that are Triaged or Resolved, and no more than 25% of their submissions can be closed as Informative or Not Applicable on the main program. Participants must maintain the same signal-to-noise ratio on the Experiments program itself, with the roster reviewed quarterly to ensure all invitees remain active and meet the bar.
A Year of Record Volume
Report volume grew sharply in 2020: Shopify received 3,093 submissions, up from 1,379 the year before. April and September were the busiest months, each topping 400 reports, coinciding with public disclosures that drew fresh interest to the program.
April brought @ngalog's findings on the Shopify ID merge flow, and September saw @francisbeaudoin's email confirmation bypass. The company credits public disclosure with improving overall report quality: it gives researchers concrete examples to learn from and keeps attention on the program.
State Breakdown and Trends
The state distribution of reports also shifted. Informative and Not Applicable classifications rose disproportionately—over 300% and 80% respectively compared with 2019—despite no policy changes. Monthly data shows spikes around the key disclosures and a steady upward trajectory.
Shopify suggests the broader trend may tie to HackerOne's revisions to Signal calculations, which could have encouraged researchers to submit more speculative Informative reports. COVID-19 restrictions may also have played a part, with more researchers at home looking to supplement income through bounties.

Despite the increased load, response times stayed close to 2019 levels. Average time to first response was 25 hours, up from 16. The team triaged 215 reports in 2020 versus 131 in 2019; triage time increased slightly from 2 days 13 hours to 3 days 11 hours. Time-to-bounty rose from 7 days 1 hour to 12 days 15 hours, largely due to the transition to CVSS-based scoring. The team now meets twice weekly to align on scores and has streamlined the process to bring that metric down.
Payouts roughly tripled: over $460,000 was awarded, compared to about $130,000 in 2019. The 50k maximum bounty introduced at the start of 2020 drove the average higher—$2,070 per bounty versus $1,139 previously.



