From 0 to your first bounty · with real reports, not toy CTFs
Bug Bounty Labs
based on real reports
practice with real bounties
Hacking labs based on real HackerOne, Bugcrowd and Intigriti reports. Download, exploit, learn. From The platform to learn bug bounty: hacking labs that replicate vulnerabilities extracted from real HackerOne, Bugcrowd and Intigriti reports. Download the environment, exploit the vulnerability and learn the technique. From €7.99/mo.
No commitment · cancel anytime · no card to explore
hunters training
labs from real reports
completions
in bounties practiced

The Spanish bug bounty community, in real numbers
No inflated metrics. No “potential users”. Just what the platform has actually delivered.
Registered hunters
Labs based on real reports
Labs solved by the community
Flags captured
Total completions
$ bounty practiced
You walk away knowing how to hunt bugs that pay. For real.
Forget toy CTFs. Here you practice with the same logic that's paying thousands of euros on HackerOne, Bugcrowd and YesWeHack every month.
You'll spot real IDOR, SSRF and RCE
Reports that paid €5k–25k tell you exactly what to look for. Learn where to look and why.
You'll practice pre and post-auth flows
Each lab simulates the context of the original bug: scope, conditions, hypotheses. Just like a real program.
You'll learn to chain vulnerabilities
The big bounties come from chains. XSS + IDOR. Open Redirect + OAuth. Race + SSRF. Learn the pattern.
You'll have writeups for your CV
Every solved lab is documented proof. Share them on LinkedIn, on your blog, or in your hunter portfolio.
All of it, by following the roadmap from 0 to your first bounty →
- 0
You start today
No prior experience
- 1
First step
1 labs
- 5
On the right track
5 labs
- 10
Solid hunter
10 labs
- 25
Standout hunter
25 labs
- 50
Top 5% global
50 labs
- 100
Hunter 1%
100 labs
Your first bounty
These are the bounties you'll learn to hunt
Every lab is based on a paid report. The reward you see is the real money the original hunter earned for finding that bug on HackerOne, Bugcrowd or YesWeHack.
Real hunters catching bugs that actually pay
Every win is real and verifiable: a BBLabs hunter solving a lab based on a bug that paid that bounty. Click any of them to see their card.
Hunters with a real track record
The creators who design the labs have taken down real programs. They're not generic instructors: they're active hunters with paid bounties.
Built by a real hunter. Not a company.
I didn't build BBLabs as just another business. I built it because I learned bug bounty by hunting real bugs — not toy CTFs with made-up flaws. It's the platform I wish I'd had: every lab is a report that paid real money. I still hunt (see for yourself), and I read every message that reaches me.
hunters training
labs from real reports
completions
in bounties practiced
Pricing
Choose how to pay for your full access
A single PRO+ plan with everything. The annual one is the most popular — almost 3 months free vs monthly. A year is how long it takes to train on real bugs, replicate them and land your first bounty. No commitment.
Flexible · cancel anytime
≈ €0.26 a day- Access to every lab, all difficulties (incl. Insane and Extreme)
- Live labs: spin up the vulnerable environment in one click
- Step-by-step writeups for every lab
- Full roadmap + shareable certificates
- Private hunters Discord
- Instant access to every new lab
€74.99/yr · you save €20.89
- Access to every lab, all difficulties (incl. Insane and Extreme)
- Live labs: spin up the vulnerable environment in one click
- Step-by-step writeups for every lab
- Full roadmap + shareable certificates
- Private hunters Discord
- Instant access to every new lab
- Early access: play new labs the moment they're scheduled, before anyone else
No renewals · forever
- 1h 1:1 call with the founder to advise you and level you up as much as possibleNEW · limited time
- Early access: play new labs the moment they're scheduled, before anyone else
- Access to every lab, all difficulties (incl. Insane and Extreme)
- Live labs: spin up the vulnerable environment in one click
- Step-by-step writeups for every lab
- Full roadmap + shareable certificates
- Private hunters Discord
- Instant access to every new lab
- Private access to the BBLABS Discord community with the best hunters
Less than half the price of HackTheBox (€168/yr) or PentesterLab (€420/yr) — and with real reports, not CTFs.
Secure SSL payment
Processed by Stripe
No commitment
Cancel anytime
+650 active hunters
Growing community
Before you decide
What if I have no experience?
The roadmap starts at Easy difficulty with step-by-step writeups, and the free Academy covers the theory of each vulnerability before you practice.
How long until I land my first bounty?
It depends on your pace, but at 1-2h a day the real jump is usually 3-6 months. The roadmap is built to get you there without skipping fundamentals.
Why not PortSwigger, which is free?
PortSwigger teaches theory with made-up labs. Here you practice with REAL reports that already paid bounties, with Spanish writeups and a clear path.
Got questions? Check the FAQ or write to us at team@bblabs.es
Comparison
BBLabs vs other platforms for bug bounty
€7.99/mo vs €11–37.99/mo. Real bug bounty reports vs gamified CTFs.
BBLabs wins where it matters for bug bounty — and costs less than half.
Start from €7.99/mo →FAQ
Frequently asked questions
A bug bounty lab is a controlled environment that replicates a real vulnerability previously reported and paid out on platforms like HackerOne, Bugcrowd or Intigriti. On BBLabs you download the environment, spin it up locally, exploit the vulnerability and validate your solution by capturing a CTF-style flag. Each lab includes a writeup with the full methodology.
You can practice bug bounty on BBLabs with labs based on real reports, from €7.99/mo. Other alternatives are HackTheBox and TryHackMe (gamified CTFs), PentesterLab (web theory, ~€37.99/mo) and the PortSwigger Web Security Academy (free, without real paid labs). BBLabs is the only one specialized in already-paid reports with a full writeup.
The shortest path: start with the free BBLabs Academy (theory of XSS, SQLi, IDOR, SSRF and CSRF), then solve Easy-difficulty labs with their writeup alongside, move up to Medium once you recognize patterns, and from there join public HackerOne or Bugcrowd programs. Each lab teaches you to think like the hunter who reported the original bug.
BBLabs is the platform specialized in bug bounty with labs based on real paid reports, hunter ranking and an active Discord community. It replicates vulnerabilities that paid out real money in production, not artificial CTF puzzles.
The labs (with a downloadable environment + flag + writeup) require a PRO+ subscription from €7.99/mo, with annual and lifetime options. The Academy —theory, payloads, cheatsheets, dictionary and per-category methodologies— is 100% free: create an account with no card and explore it without paying anything.
More than 16 web vulnerability categories: XSS (reflected, stored and DOM), SQL Injection, IDOR, SSRF, CSRF, Open Redirect, Race Conditions, Path Traversal, API Abuse (mass assignment, BOPLA), Business Logic, Auth Bypass, RCE, XXE, SSTI and more. Every category is fed weekly with new labs based on recent reports.
Our labs replicate vulnerabilities that paid real bounties on HackerOne, Bugcrowd and Intigriti. They're not artificial CTFs. It also costs €7.99/mo (vs €14–37.99/mo from competitors) and includes a free Academy with payloads and methodologies.
PortSwigger is excellent theory, and we actually recommend using it. But its labs are exercises designed to teach a concept, not replicas of bugs that paid real money. On BBLabs you practice exactly what a hunter found in production and got paid for, with the real program context and a full writeup. It's the difference between solving an exam exercise and reproducing the real case that paid €5,000.
There are dozens of labs covering more than 16 vulnerability categories, and we publish a new one every Monday. The full Hunter Roadmap (from Easy XSS up to Insane/Extreme) takes months to complete even for advanced hunters. You won't run out of practice.
Yes. Labs range from Easy to Insane difficulty. Each one includes a step-by-step writeup with the full solution. The free Academy teaches you the theory of each vulnerability before you practice it. You'll learn by doing, not by reading.
Yes. Every lab replicates a vulnerability reported in real bug bounty programs that paid real money. You practice with what actually shows up in production, not with made-up puzzles.
Yes, with no commitment or penalty. Cancel from your panel at any time and keep access until the end of the paid period. No fine print.
Every Monday we publish new labs based on recent reports. The content is updated constantly with the latest techniques that are working in active programs.
Visa, Mastercard, Apple Pay and Google Pay through Stripe. Secure payment with SSL encryption. We also offer an annual plan with 22% off and a one-time lifetime plan.
// academy, company or event?
Put BBLabs in your team's hands
Per-cohort licenses, custom CTFs and co-branded certificates.



