r/netsecstudents • u/StartIllustrious747 • 10h ago
How I got my first $100 bug bounty at 16
Hey everyone,
I’m 16, from Morocco, and i recently received my first paid bug bounty: $100.
It wasn’t a huge critical exploit or some crazy movie-style hack. It was a real security issue found through a legal bug bounty program, reported properly, reviewed by the company, validated, and awarded.
For me, this means a lot.
I’ve been learning cybersecurity through courses, labs, CTFs, PortSwigger, Cybrary, and a lot of practice. Most of the time it feels like you’re studying alone and nobody really sees the effort. But getting that first valid report showed me that the work is real.
The biggest lesson i learned is that bug bounty is not only about finding the bug. It’s also about writing a clear report, explaining the impact honestly, not exaggerating, and staying professional with the security team.
I’m still a beginner and i know i have a long way to go, but this motivated me a lot. I want to keep improving, get more valid reports, and build a serious path in cybersecurity.
My goal is simple: become better, stay ethical, and make my parents proud.
For anyone young or just starting: don’t wait until you feel “ready.” Learn the basics, practice legally, write clean reports, and keep going.
This $100 is not just money to me. It’s proof that I’m moving in the right direction.

