OWASP BLT: Secure the Web, Get Rewarded

Strengthen worldwide applications by finding and fixing security & coding issues through bug bounties and issue rewards. Earn money via GitHub Sponsors & BCH and get recognized with BACON, the first open-source security token on Bitcoin Runes.

Protect Applications

Safeguard your applications from security vulnerabilities.

Earn Rewards

Get rewarded for your security findings.

View Bounties

Automate Security

Streamline your security workflows.

NEW

Learn & Grow

Access expert-led security courses.

Start Learning

Recent Hackathons

Join our coding competitions, collaborate with the community, and win amazing prizes!

Security Hackathon 2024

Active

Organized by OWASP

Join us for an exciting security hackathon where you can compete with other security researchers and win amazing prizes!

Nov 01, 2024 - Nov 30, 2024
View Details

Web Security Challenge

Upcoming

Organized by BLT Community

Test your web security skills in this comprehensive challenge covering various vulnerability types and exploitation techniques.

Dec 01, 2024 - Dec 15, 2024
View Details

Community Leaderboards

Total Bounties Earned: $155

Top Earners

$50.00
$35.00
$25.00

Top Bug Reporters

45 bugs
32 bugs
28 bugs

TOP BLT PRs - Nov

Top Referrals

20 pts 10
16 pts 8
12 pts 6

Our Components

Four key components power OWASP BLT. The core, mobile access, browser integration, and automation—working together to secure applications worldwide.

The main engine powering OWASP BLT's system API and Slack Bot.

Mobile application for on-the-go bug reporting and management.

Browser extension for quick bug reporting and screenshots.

GitHub Action for automated security checks and reporting.

Join Our Referral Program

Sign in to get your referral link and start earning points!

Latest Activity

Latest Bug Reports

XSS vulnerability in search form

Open
3 hours ago
15 High
View Details

SQL injection in login page

Resolved
1 day ago
28 Critical
View Details

Latest Blog Posts

Top 10 Security Vulnerabilities in 2024

SecurityEditor 3 days ago

Explore the most critical security vulnerabilities discovered this year and learn how to protect your applications from these threats...

Read more

Getting Started with Bug Bounty Programs

BountyExpert 1 week ago

A comprehensive guide for beginners looking to start their journey in bug bounty hunting and ethical hacking...

Read more

Corporate Supporters

BLT is an official OWASP project, adhering to the highest standards of open-source security.

Sentry provides BLT with a free plan for error monitoring and performance tracking.

Google supports BLT through Google Summer of Code, fostering student contributions.

Donate to the BLT project to support our development and have your logo featured here. Become a Supporter

Get Involved

Join our community and help make the internet a safer place.