I Earned $2M Hacking. Here's Everything I Know

I Earned $2M Hacking. Here's Everything I Know

Source: YouTube · NahamSec · published Mar 30, 2026 · 15:02

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The speaker shares their inspiring journey from struggling in tech to making over $2 million through bug bounties, proving that formal education is not a prerequisite for a highly successful cybersecurity career 0:00.

Key Takeaways:
• The journey began 12 years ago when the speaker earned $9,000 from finding three simple SQL injection bugs on Yahoo while living in a small apartment 0:00.
• Early academic struggles, including failing a Java class twice, initially left the speaker genuinely doubting their future in the tech industry 0:13.
• Through persistence, they eventually amassed over $2 million in bug bounty earnings, with peak payouts of $650,000 in a single year and $200,000 in one month 0:29.
• Their notable accomplishments include winning HackerOne's "most valuable hacker" award and successfully identifying vulnerabilities in massive corporations like Apple, Amazon, Airbnb, and Facebook 0:38.

This story highlights the lucrative and accessible nature of bug bounty hunting, demonstrating that practical hacking skills can far outweigh traditional academic credentials.

Sources:

  • 0:00 Initial $9,000 earnings from Yahoo SQL injection bugs
  • 0:13 Failing Java twice and doubting tech career prospects
  • 0:29 Reaching $2 million in total bug bounty earnings
  • 0:38 Hacking major tech companies and winning a HackerOne award

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

12 years ago today, I was sitting on the floor of my tiny one-bedroom apartment staring at my bank account $9,000 from three simple sequel injection bugs that I had found on Yahoo. My rent at this point in life was roughly around $600 a month. I had just failed my Java class twice and I genuinely didn't know if I was going to make it out in tech. And I remember thinking in that tiny apartment, holy I just made this. What else can I do here? Where else can I take this? Fast forward to today, I've made over $2 million with bug bounties and 650,000 of that came from a single year and I think about 200 of it was in a single month. I've won the most valuable hacker award for one of HackerOne's events. I've hacked into companies like Apple, Amazon, Airbnb, Facebook and you name it. And on top of…