[CORE] YesWeHack credits
Key changes
A new submission model has been implemented in the platform. The current submission constraint (‘Accepted, Duplicate, Resolved’ reports’ ratio) has been replaced with a new credit-based system for submitting vulnerability reports on Bug Bounty and Featured VDP programs.
Each program now requires a specific number of credits to submit a report. Hunters recover the credits they spent when their report is accepted and receive a bonus. They can also earn an additional bonus based on the report's severity.
Impact
This feature helps limiting the number of low-quality reports submitted on the platform (e.g., AI-generated reports and spam)
Therefore, it reduces the time the triage team needs to assess vulnerability reports from serious Hunters.
Audience
All YesWeHack Hunters
All Bug Bounty and Featured-VDP programs
Usage
ℹ️ Learn more about the YesWeHack credits here.
As a Hunter,
Go to “My programs” where you can see the cost of a submission on each card
Open a Bug Bounty program
Each program includes a “Credits” section that displays the cost of a submission
[EM] Attack surface multi-programs
Key changes
Organisations can now create multiple attack surface programs to reflect their internal structure (e.g., teams, entities or subsidiaries) and set separate access rights for each program.
Impact
By enabling the creation of multiple attack surface programs, this feature helps organisations better manage their assets and reduces the risk of internal information leaks.
Audience
All Exposure Management and Continuous Pentesting customers
Usage
ℹ️ You must be a Business unit owner (BUO), a Business Unit Manager (BUM) or Business Unit Surface Manager (BUSM) to create a Surface program.
Go to “Admin Panel”
Click on “+ Surface”
Fill in the “Title” field
Click on “Create”
Your Surface program is now created. Add primary assets to complete your program.
ℹ️ Learn more about how to set up a Surface program here.
[MISC]
[Hunters] Hunters can now export a Bug Bounty program's scope list directly from each program card in the Admin Panel for use in their tools (e.g., Burp Suite).




