Find Any HackerOne Username with WhatsMyName App
HackerOne runs bug bounty and vulnerability disclosure programmes for a large share of the technology industry, paying out 81 million dollars to researchers in the twelve months to June 2025. A researcher's handle there is their professional reputation, publicly attached to their work. WhatsMyName App checks one alongside 731 other platforms in a single search.
Platform: Security, bug bounty · $81 million paid to researchers in twelve months
Search HackerOne Username FreeWhat Is HackerOne and Why Username Searches Matter
HackerOne connects organisations running bounty programmes with the researchers who find vulnerabilities in them. Payouts rose about 13 percent year on year to 81 million dollars over that twelve month period, which gives some sense of the scale at which this operates as a profession rather than a hobby.
Every researcher has a public profile at hackerone.com/handle carrying their reputation score, signal and impact metrics, the programmes they have participated in and any disclosed reports they have chosen to make public. Those disclosed reports are the substantive part: they are technical write ups with the researcher's name on them, and they function as a portfolio.
The reason handle checking matters here is that security work runs on reputation and reputation attracts imitation. Companies vet researchers who approach them directly. Researchers verify each other before collaborating. And organisations receiving an unsolicited vulnerability report, particularly one that arrives with a demand attached, need to know whether the person contacting them has a real track record or is running a shakedown.
How HackerOne Usernames Work
The handle is the whole profile address at hackerone.com/handle. The check WhatsMyName App runs queries HackerOne's own API and asks whether a user resolves at that name, so a confirmed result reflects the platform's own answer rather than an inference from a rendered page.
Handles in this community are professional identities and behave accordingly. Researchers build reputation under one name over years, present at conferences under it, and are cited by it in advisories and CVEs. That persistence is what makes the handle worth checking rather than the display name, which can be anything.
Reuse with the wider security cluster is high. The same handle usually resolves on GitHub with tooling and proof of concept code, often on Keybase, and frequently on X where disclosure discussions happen. A handle presented as an established researcher that exists only on one platform, with no disclosed reports and no code anywhere, does not match how the profession works.
- Profile URL format: hackerone.com/handle
- Profiles carry reputation, signal and impact metrics
- Publicly disclosed reports act as a technical portfolio
- Handles persist for years and appear in advisories and talks
- High overlap with GitHub, Keybase and X
How to Search a HackerOne Username with WhatsMyName App
No account, no install, no cost. Results in under 90 seconds.
Go to WhatsMyName App
Open whatsmynameapp.us in any browser. No account needed.
Take the handle
Copy the part of the profile address after hackerone.com, or the handle quoted in the message you received.
Run the search
Type it into the search bar and click Search. All 732 platforms are checked in parallel, including HackerOne.
Find the HackerOne result
Results stream in as checks complete. Look for the HackerOne entry showing confirmed or not found.
Read the disclosed reports
Open a confirmed result and look at what the researcher has published. Disclosed reports are the substantive evidence of real work.
Check the security cluster
Look at the GitHub, Keybase and social results in the same scan. Working researchers publish tooling and proof of concept code.
Export the results
When the scan finishes, export every found account to CSV if you are handling an inbound report formally.
What WhatsMyName App Shows for HackerOne
A confirmed result links to the public profile. Reputation and signal are useful summary numbers, but the disclosed reports are what actually tell you something, because they are technical work with a name attached that other people have reviewed. A profile with real disclosures behind it is difficult to fabricate.
A not-found result means HackerOne does not report a user at that handle. Plenty of legitimate researchers work through other platforms or directly, so this is not evidence of bad faith by itself. It is, however, a good reason to slow down if the person presented a HackerOne reputation as their credential.
Ready to check a HackerOne username?
Open WhatsMyName AppAfter Finding a HackerOne Account
If you have received an unsolicited vulnerability report, separate two questions. The first is whether the finding is real, which your own engineers answer and which does not depend on who sent it. The second is whether the sender is who they claim, which is what this check addresses. A real bug from an unverifiable stranger is still a real bug.
The pattern that should raise concern is a payment demand attached to a threat of disclosure, particularly from a handle with no verifiable history. Legitimate researchers work through a programme's disclosure process, and their reputation depends on doing so visibly. Someone bypassing that while invoking a reputation they cannot demonstrate is doing something else.
If you are a researcher, your handle is the asset. It carries your reputation across platforms, appears in advisories that outlive any single engagement, and is what people search when deciding whether to engage with you. Knowing what a full scan of it returns is worth the minute it takes.
- A real vulnerability is real regardless of who reported it
- Payment demands plus disclosure threats plus no history is the shakedown pattern
- Disclosed reports are the hardest part of a profile to fake
- Researchers: the handle outlives every individual engagement
Related Platform Searches
WhatsMyName App checks these platforms alongside HackerOne in a single search. Explore the guides below or browse all OSINT tools available on this site.
Working researchers publish tooling and proof of concept code, so a matching GitHub with real commits is strong corroboration.
Keybase ties a handle to cryptographic proofs across platforms, which is the closest thing to identity verification in this community.
A long technical history under the same handle adds years of context that a bounty profile alone does not.
People who reuse a handle on HackerOne tend to reuse it on these too:
Every platform guide on this site is listed on the WhatsMyName App guide.
Frequently Asked Questions about HackerOne Username Search
How do I verify a security researcher's identity?
Search their handle in WhatsMyName App, open the HackerOne result and read their publicly disclosed reports, then check whether the same handle has GitHub tooling and a Keybase presence.
What does a HackerOne profile show?
Reputation, signal and impact metrics, the programmes the researcher has participated in, and any reports they have chosen to disclose publicly. The disclosed reports are the substantive evidence.
Someone reported a vulnerability and wants payment, what should I do?
Treat the finding and the sender as separate questions. Have your engineers assess whether the bug is real, and check the handle independently. A payment demand paired with a disclosure threat from a handle with no verifiable history is the shakedown pattern.
Does no HackerOne profile mean someone is not a real researcher?
No. Many legitimate researchers work through other platforms or directly with organisations. It is only significant if they presented a HackerOne reputation as their credential.
Why are researcher handles so stable?
Because reputation is the profession's currency. Researchers build it under one name over years, present under it, and are cited by it in advisories and CVEs, so abandoning a handle means abandoning the record.
Is checking a HackerOne handle legal?
I am a researcher, why check my own handle?
Because it is your professional identity and people search it before engaging with you. Knowing what the full scan returns tells you what a prospective programme or collaborator sees.
Search Any HackerOne Username Now
WhatsMyName App checks HackerOne and 731 other platforms simultaneously. Free, no sign-up, results in under 90 seconds. Read the full WhatsMyName App guide to get the most out of every search.
Run a HackerOne Username Search