Our PracticeTeamPricingConsultingInvestorsGet Started
← All Field Notes
June 13, 2026 · by Ravsecurityharm-reductioneconomicspolicybug-bountyopinion

Pay the Hackers

We spend a fortune fighting the people who find our holes, and nothing rewarding them for finding them. After watching a teenager with a useful tool and no legitimate buyer turn to crime, I think the whole model is backwards. You're going to pay either way — to fight or to cooperate. Here's the case for cooperation, and why it's closer to reality than it sounds.

A teenager broke into one of our servers this spring. By the time we'd untangled it, I'd learned something about him that bothered me more than the break-in: the one tool he actually built himself — a scanner that crawls the internet finding websites with holes — he'd originally built to go legitimate. Find the vulnerability, tell the owner, get paid to fix it. A real business. The white-hat version of exactly what he ended up doing for crime.

It didn't work. Not because the tool was bad — because he couldn't get a single person to care. And the same tool that found no paying customers as a service found instant value the moment he pointed it at the open internet with bad intent. He didn't lack a moral compass. He lacked a buyer.

I've been chewing on that for weeks, and I've come around to a position that sounds crazy for about thirty seconds and then stops: we should pay the hackers.

You're paying either way

Start with the number nobody wants to look at: the security industry is enormous, and almost all of that money is spent fighting. Detection, response, compliance, the endless arms race against people changing their tactics faster than we can write rules. We have decided, as a culture, to spend our security budget on combat.

Here's the thing about a fight: you pay for it whether you win or lose. And when you lose — when you "get got" — you pay again, in cleanup and breach costs and the quiet tax of never being sure you got them all. The money was never the question. The only question was what it bought.

So I'll put it bluntly. You are going to pay either way. You can pay to fight, or you can pay to cooperate. And cooperation, it turns out, is cheaper — because a vulnerability someone tells you about costs you a bounty, while the same vulnerability someone uses costs you a breach. Same hole. Wildly different bill.

The hackers gonna hack

We already know prohibition doesn't work, because we ran the experiment in every other domain. You don't eliminate drug use by criminalizing it harder; you reduce the harm by meeting the behavior where it is. Portland put sharps containers in public bathrooms not because it endorses heroin but because the needles are going to be there regardless, and a container beats a gutter. Needle exchanges, methadone — the whole harm-reduction playbook wins not by stopping the behavior but by pricing its harm down and its cooperation up.

"The hackers gonna hack" is the same true premise as "the users gonna use." There will always be curious, capable people probing the open internet, for money, for status, for the sheer itch of it. You cannot make that population go away. You can only decide whether their energy flows into your wound or into your defense.

The monkey presents its back

The cleanest version of what I'm proposing is something nature already solved. Watch two monkeys groom each other. One presents its back; the other picks the ticks and gets a meal. It is a perfect little economy — the groomer is allowed into the vulnerable spot, on purpose, and both walk away better. Parasites removed, belly filled.

The whole thing works on one word: invitation. The back is presented. That offer is the entire difference between grooming and predation — and it is exactly the difference between a researcher and an intruder. Same hands, same access to the soft spot. One was invited in; one forced its way.

This is the part that makes "pay the hackers" rigorous instead of insane. You do not pay the one who grabbed you by the throat. You make every system present its back by default — build a standing, universal invitation, a front door marked here is how to tell me I have a hole, and here is what it's worth to you — and then you let the economics do the sorting. When the invited path pays and the forced path doesn't, the rational actor rings the doorbell. You haven't rewarded the break-in. You've made the break-in the stupider option.

This is already happening — you're just early

If this still sounds utopian, look at where the ground has already moved:

  • The DOJ stopped prosecuting good-faith security research under the Computer Fraud and Abuse Act. The legal carve-out that says "finding a hole in good faith is not a crime" is partly built.
  • security.txt is now a published internet standard (RFC 9116) — a small file a website can host that says, in machine-readable terms, here is how to report a vulnerability to me. That is the monkey presenting its back, written as a protocol.
  • Vulnerability disclosure policies are mandated for US federal systems. The "present your back" requirement is becoming law, from the top down.

The culture and the law are already bending toward the invitation. The shift I'm describing isn't a fantasy. It's a trajectory, and we're a few steps ahead of where it currently sits.

Where it works, and where it doesn't

I want to be honest about the edge, because the honest version is more persuasive than the hype.

"Pay more than the crime pays" works beautifully for the long tail — the small business, the dentist's office, the four million commodity websites a kid's scanner can chew through in a week. For those, a black-market exploit is worth pennies, and a modest bounty easily outbids it. The math is lopsided in cooperation's favor.

It breaks at the apex. A crown-jewel exploit against a major bank is worth millions to a criminal, and no bounty on earth will outbid that. Fine. The apex already has armies of defenders and bottomless budgets and isn't the problem I'm trying to solve. The problem is the 99% that has nothing — no bounty, no disclosure policy, no door, no buyer for the kid who found their hole. That population is enormous, undefended, and currently served only by the people willing to break in.

The cheapest defense force on earth

So here is the whole argument in one breath. The largest pool of would-be intruders on the planet is also the largest pool of latent vulnerability-finders on the planet — they are the same people. Right now we spend billions making them our enemies and zero making them our scouts. Flip one incentive — make telling you worth more than using it, and make the door to tell you exist everywhere by default — and you convert that entire population into the cheapest, most distributed defense force ever assembled.

We've already started

I should be honest about where this comes from: we didn't reason our way to "pay the hackers" and then go shopping for a product to prove it. We built the product first, on instinct, and only later worked out what it was.

After the miners kept coming back, we made a tool that catches them by behavior — and added the part that matters here. When it catches a miner on your machine, it can report that attacker's fingerprint — the wallet, the pool, nothing about you — to a shared network. Anonymous by default; your own address is discarded the instant it arrives. Opt in, and you get a receipt, and you can watch your report get corroborated by other people's machines and the wallet flagged across the network. One person's infection becomes everyone's immunity — and the people supplying the intelligence are exactly the ones the attack happened to. That's present the back, shipped: every install is a system that has chosen to be looked into, on purpose, in exchange for the protection of every other install.

There's exactly one thing it doesn't do yet: pay. A contribution earns a receipt and the quiet satisfaction of watching an attacker's wallet die — reputation, not money. But the ledger underneath it — who reported what, which reports got confirmed — is the same ledger you'd write a check against. We didn't skip the paying because wiring money is hard. We left the slot open because how you reward finders fairly is the part worth getting right first.

So "build the other version" isn't something I'm asking someone else to fund. It's something we're halfway into — the hard half, the consensual collective-immunity part, already running; the paying half deliberately left as the next move.

The kid, again

The kid who broke into my server wasn't a monster, and he wasn't even a great hacker. He was a capable person standing in front of a market that had no slot for the good version of what he could do. I couldn't reward him. The law has no place to put "the kid who showed me my own front door." That's not his failure. That's a market that didn't exist for him — and the thing worth being angry about isn't that he hacked me. It's that, for a person like him, hacking me was the only version of his talent anyone was willing to pay for.

Build the other version. Present the back. Pay the finders. It's cheaper than the fight, and you were always going to pay anyway.