Netscape launched the first public bug-bounty program in 1995.
The initiative began after Netscape employees noticed that some users and developers were enthusiastically finding and reporting flaws in the company’s browser. Instead of treating every finder as an adversary, Netscape publicly encouraged responsible reports and offered recognition or rewards.
This approach helped establish a model now used throughout the technology industry: researchers disclose security weaknesses privately, organizations investigate and fix them, and qualifying discoveries may receive money or public credit. The program was associated especially with Netscape Navigator and its rapidly evolving web software.
Bug bounties are not the same as penetration testing. A penetration test is commissioned under a defined contract, while a public bounty program invites eligible independent researchers to test within published rules. Rewards, scope, and legal protections vary widely between programs.