Buy Hackhub: Bug Bounty DLC PC Key

This content requires the base game: HackHub - Ultimate Hacker Simulator
★ ★ ★ ★ ★

When does Hackhub: Bug Bounty come out? The game has not reached any of the stores we track yet, so there is no price so far. Once the first offers appear we will start recording their history from release day, so later you will be able to see how the price moved from the start. Set an alert and we will write when the game goes on sale. This is an add-on, so you also need the base game to play it.

Release: 30 Oct 2026
HotBunny
Official
Unavailable
Keyshops
Unavailable
Buy in Official Store:
Unavailable
Buy in Keyshops:
Unavailable

No entries, but don't worry, we will inform you once the new offer appears.

Create Alert Create deal Alert

About Hackhub: Bug Bounty

Hackhub: Bug Bounty - about the game
Bug Bounty is a career pack. You sign up to HackerNone, a coordinated disclosure platform, and companies pay you for security flaws you can prove in their websites.

Nobody tells you where the bugs are. A programme page gives you a scope list, a policy, a payout table and how picked-over the target already is. Everything else is browsing the site, reading its JavaScript, running recon in the terminal, and noticing the one thing that does not add up.
Finding it
The pack installs Borp, an intercepting proxy, as a desktop app. Proxy the browser through it and every request lands in the history. Hold one in flight and rewrite it before the server sees it, or send it back by hand through Repeater as many times as you want, with whatever headers you want. Findings that produce nothing visible are proved with the collaborator: your payload calls out to a domain that logs the hit, and that log line is the evidence.

Twenty-four weakness classes are implemented, all of them real ones: IDOR, broken access control, JWT signature bypass, SSRF, path traversal, stored and blind XSS, SSTI, host header injection, subdomain takeover, secrets committed to source, business logic, race conditions. Each target's flaw genuinely exists in its simulated server. There is no scripted flag to walk into.
Reporting it
Finding the bug is half the job, and the report is not a text box.

Borp records what you did. To write the reproduction you drag the relevant steps out of that log, put them in order, and mark which ones are evidence. Then you classify the finding: which asset, which weakness, and a set of plain-language questions that build the CVSS vector for you. Impact in your own words. A fix, if you have one worth suggesting.

A triager reads it a few game hours later and answers in the thread. Triaged, then Resolved with a payout once they ship the fix. Needs more info, because your steps do not reproduce. Duplicate: you were right and you were slow. Informative: true, but not worth money to them. Not applicable, which is the only verdict that costs you anything.
The targets
Ten companies, hand-written, roughly in difficulty order.

  • Sprocket Supply runs a disclosure-only programme. No bounties, forgiving triage, and an order endpoint that checks you are logged in without checking the order is yours. The tutorial lives here.
  • Kestrel People and Peppermint reward recon over exploitation: admin routes sitting in a script bundle, a live mail key in shop.js, a subdomain still pointed at a host nobody owns any more.
  • Lumen Notes and Atlas Docs are competent builds with one bad assumption each, in token validation and in path filtering.
  • Vantage Analytics opens at 70 reputation and its bug is blind, so you will need out-of-band proof to say anything about it.
  • Northwind is a marketplace with rate limits and honeypot paths that earn you a warning email if you walk into them. Anything obvious here has already been reported by someone else.
  • Meridian Bank is invitation only: narrow scope, strict policy, your own account or nothing.
  • Fitric has a mobile app and no web surface worth testing. Decompile the APK and work from what is in the strings.
  • Corveil gives you read access to its repository. The finding is a file and a line number, and the report is a code review.

After those, procedural programmes keep arriving. Every generated company gets its own web app, API, test account and a flaw you can actually exploit, and the hunters on the leaderboard keep gaining reputation on the game clock whether you are playing or not.
Standing
Two numbers do the work. Reputation is your career total, never drops, and unlocks the tiers: startups, SaaS, big tech, critical infrastructure. Signal is the average worth of your reports, and Signal is the one with teeth. Duplicates leave it alone. Filing twenty guesses in the hope that one lands drags it down, and the programmes at the top of the ladder quietly stop reading hunters whose Signal is bad. Get it high enough and private invitations start arriving.
The case
Mara Vega triages for a few of the programmes and spots a pattern in your rejections before you do. A hunter called dup3_king is filing duplicates of your reports about four minutes after you submit them, which is not possible unless somebody is reading the queue.

Six chapters, ending at a case desk with two buttons and a price behind both of them. A second thread runs alongside it: Meridian closed a critical as Won't Fix, a ninety day disclosure clock starts, and someone offers you a retainer to let it run out quietly.
Everything else in the pack
  • Timed live events on a single shared target, scored on severity and report quality, with bonuses for the best bug and the most creative chain, and cash and reputation for the top finishers.
  • Triage work as a paid job once your Signal is good enough. Read other hunters' reports, rule on them, and get paid per correct call.
  • Eight terminal tools that behave like the originals: amass, ffuf, arjun, gitleaks, jwt-tool, waybackurls, apktool, and a passive monitor that surfaces new assets days later while you are busy elsewhere.
  • A sixteen article handbook on scope, severity, report writing and each bug class, plus HackTales, a writeup blog by in-game hunters that teaches the techniques without naming the targets.
  • A broker who turns up after your first accepted critical, offering roughly five times the bounty for the exploit and your silence.
  • Four achievements.

The companies are fictional. The bugs, the tools and the paperwork are not.
Interface:
ArabicBulgarianCzechDanishGermanGreekEnglishSpanish - SpainSpanish - Latin AmericaFinnishFrenchHungarianIndonesianItalianJapaneseKoreanDutchNorwegianPolishPortuguese - PortugalPortuguese - BrazilRomanianRussianSwedishThaiTurkishUkrainianVietnameseSimplified ChineseTraditional Chinese
Audio:
English
Subtitles:
ArabicBulgarianCzechDanishGermanGreekEnglishSpanish - SpainSpanish - Latin AmericaFinnishFrenchHungarianIndonesianItalianJapaneseKoreanDutchNorwegianPolishPortuguese - PortugalPortuguese - BrazilRomanianRussianSwedishThaiTurkishUkrainianVietnameseSimplified ChineseTraditional Chinese
Historical low
Price history from official stores
-
-
-
Price history from keyshops
-
-
-
Join our Discord
Get instant help from our community and stay updated on the latest deals
Set Price Alerts
Get notified by email when game prices drop to your target
Create Free Account
Unlock wishlists, price alerts, and Steam sync

FAQ

8 questions

Before you start looking for a cheap Hackhub: Bug Bounty PC key, check the essentials. Developed by HotBunny. Published by Games Operators. PC released date: 30 Oct 2026. Genres: Strategy, Indie, Simulation. Categories: Multi-player, PvP, Online PvP, Family Sharing, Steam Workshop, Single-player, Downloadable Content, Cross-Platform Multiplayer, Steam Achievements, Steam Cloud, Adjustable Text Size, Custom Volume Controls, Playable without Timed Input, Save Anytime, Stereo Sound, Surround Sound, Subtitle Options.

Q

Where to buy a cheap Hackhub: Bug Bounty Steam key or CD key?

There are currently no active offers for Hackhub: Bug Bounty. Set a price alert on XD.deals and we will notify you the moment a deal becomes available.

We don't have a current Steam Store price for Hackhub: Bug Bounty. The game may be temporarily unavailable or not yet listed on Steam.

Our price tracker covers both official retailers and key marketplaces, so you can find Hackhub: Bug Bounty on sale even outside seasonal promotions. We currently detect 0 active offers from official stores and keyshops. Check the table above, compare against the historical low, and set an alert so you never miss the next price drop.

Based on our data, Hackhub: Bug Bounty is not currently available on GeForce NOW. You will need to run it locally on your PC. Browse games available on GeForce NOW.

Yes. Hackhub: Bug Bounty has an official page on the Steam Store, but we currently don't track any third-party offers with Steam DRM. Check back later or set a price alert.

Not at this time. Valve marks Hackhub: Bug Bounty as Unsupported on Steam Deck. Keep an eye on XD.deals - we track Proton updates and community fixes. Browse games that are Steam Deck Verified or Steam Deck Playable.

According to our data Hackhub: Bug Bounty is not currently available on PC Game Pass, EA Play or Ubisoft+. We are still filling in the catalogues of these services, so it is worth confirming the status at the source before you decide. If you are buying, XD.deals will help you find the lowest price.

No - XD.deals is not a store. We are a price-comparison service that tracks the best Hackhub: Bug Bounty deals across official stores and verified keyshops. Click "Go to Store" next to any offer and you will be redirected to the retailer's website to complete your purchase.

Want to buy at the best moment? Set a price alert on XD.deals and get notified when Hackhub: Bug Bounty hits its next historical low.

Create Alert