If you click on a link and make a purchase we may receive a small commission. Read our editorial policy.

Valve offers bounties for Steam bug hunting

Developer and storefront owner has paid out over $108,000 in bounties so far

Valve has joined companies such as Nintendo, Microsoft, Riot Games, and Rockstar Games offering to pay bounties to hackers who find exploits in its sites and services through HackerOne. Already, over $100,000 in bounties have been paid out.

HackerOne is a platform that connects companies with white hat hackers by offering bounties for found bugs reported through the program. Through HackerOne, companies can place limitations on the kinds of exploits hackers are allowed to perform to discover the bugs and where they're authorized to look.

For example, Valve's bounties allow for exploits found on the Steam Client and other Valve websites, but excludes certain third-party-run Valve store sites. Hackers are also asked not to DDoS, social engineer, or spam to discover bugs.

Bugs found in individual games launched through the Steam client should stll be submitted through the Support site and are not eligible for bounties.

The minimum bounty for reporting a qualifying bug to Valve through this program is $100, with payouts up to $2,000 or more for particularly grievous issues. So far, the average bounty range paid out is $350-$500, and the highest bounty paid has been $3,000.

Related topics
Author
Rebekah Valentine avatar

Rebekah Valentine

Senior Staff Writer

Rebekah arrived at GamesIndustry in 2018 after four years of freelance writing and editing across multiple gaming and tech sites. When she's not recreating video game foods in a real life kitchen, she's happily imagining herself as an Animal Crossing character.