← Blog
3 min read

How to find a bug bounty teammate you can actually trust

collaboration reputation getting-started

Solo hunting has a ceiling. You are good at web, but the target is a mobile app. You found the vulnerability, but chaining it to real impact needs someone who lives in the cloud console. The bounty is right there — and you cannot reach it alone.

So you do what everyone does: post in a Discord, slide into a Twitter DM, ask in a Telegram group. And then the real problem starts. Who is this person? Did they actually find what their profile claims? If you hand over your half-finished exploit, will they still be here tomorrow, or will they report it solo and keep the whole payout?

This is the part nobody solved. Platforms like HackerOne and Bugcrowd let you split a reward — but only with someone you already trust. They never help you find that someone.

Complementary skills beat duplicate skills

The instinct is to team up with someone who works like you. Resist it. Two web hunters find the same bugs twice. A web hunter and a mobile hunter find bugs neither could reach alone.

Before looking for anyone, write down two lists:

  • What you own. The specialties where you are genuinely strong — web, API, mobile, cloud, reversing.
  • What keeps stopping you. The targets you skip, the reports you cannot push to critical, the platforms you never touch.

The second list is your teammate's first list. Search for the gap, not the mirror.

Verify the person before you verify the bug

A stranger's claim of "senior, 200 valid reports" means nothing on its own. Reputation only counts when it is tied to something you can check:

  1. A linked, public track record — a real HackerOne or Bugcrowd profile you can open in one click, next to the claim.
  2. Evidence of how they collaborate, not just how they hack. Did past partners get paid what was agreed? Did they disappear mid-engagement?
  3. A trail you did not have to take on faith. The most valuable signal is the one that only exists because real people worked together and said so afterward.

Skills tell you whether someone can help. Reputation tells you whether you will regret it.

Agree the split before the work, in writing

Most collaboration disputes are not about hacking. They are about a split that was never actually agreed, only assumed. Settle it before the first shared note:

  • Decide the percentages up front. 50/50 is fine. So is 70/30 when one person brings the initial finding. What is not fine is "we'll sort it out later."
  • Write down who does what. Finding, escalating, writing the report, handling triage back-and-forth — each has real cost.
  • Name the tie-breaker. If the program pays less than expected, or asks for more work, decide now how you handle it.

None of this needs a lawyer. It needs one message both people agree to before any real value changes hands.

Where Bounterland fits

Bounterland exists for exactly the gap above: discovery plus trust. Filter hunters by specialty, platform, language and availability to find the complementary skill you are missing — then judge them on reputation that is earned through real, completed collaborations, not self-declared. You find the person; the trail tells you whether to trust them.

The bounty was never the hard part. Finding the right person to split it with was. That is the part we are building.