In the age of AI, the hacker atop our all-time and 2026 leaderboards said he automates less of his Bug Bounty workflow than peers might suspect.
In an interview with YesWeHack, Issam Rabhi reflected on his rise to dominance and the habits behind his success.
Rabhi walked us through his tools and methodology, reeled off his favourite vulnerability types and some off his best finds so far, and offered tips for up-and-coming hackers.
He also takes us back to the Wild West of vulnerability disclosure before Bug Bounty platforms became established.
And the father of two, who combines Bug Bounty with a day job in InfoSec consultancy, discussed his downtime and the importance of a healthy work-life balance for busy hackers.
Rabhi on becoming a hacker…
How did I become a hacker? It goes back a long way because I’m 40 years old. It goes back to when I was a child. It started when I was very interested in video games: how to hack, how to win without playing well, but with little tricks by doing reverse engineering. So I was interested in that and, little by little, it became second nature.
I followed an academic path. I did a PhD in computer science and then I became a research engineer at INRIA [National Institute for Research in Digital Science and Technology]. I also learned on my own.
On disclosing vulnerabilities in the days before the Bug Bounty model gained traction…
I started in 2009/2010 and was one of the first, because I remember the first goodies I got from Yahoo. There were coupons to buy little goodies, and PayPal sent me a t-shirt – there was no monetary aspect involved. I was among the first to receive gifts. That's because there was no other way.
At the time, there was no way we could [legitimately report] a vulnerability. It was almost not allowed. So we sent what we found to Zataz, [a cybersecurity news site] which still exists, and which actually acts as a buffer: passing on information behind the scenes while hiding our identity. The aim is to patch the bug afterwards.
On his methodology and talent for spotting productive research avenues…
I believe expertise comes with experience. I have gained a great deal of maturity. I have my own tools, but I also have my own methodology that allows me to quickly and effectively detect vulnerabilities.
I have an instinct for going to the right place at the right time before everyone else. I can’t explain it, unfortunately, but over time I've realised that I can gain a bit of an advantage in terms of speed compared to others because I know, with the little research I do, where to prioritise, what scope and with what parameters.
On his preferred tooling and automation…
The must-have tool is Burp Suite. In fact, even though I have tools that help me with reconnaissance, I confess that I do a lot of manual work. I know people think I'm all about automation, but no, I only automate reconnaissance, which gives me an accurate picture of what I’m looking for.
But after that, I prefer manual tests, which allow me to understand what the application is for and how to inject.
On his favourite types of vulnerability…
The vulnerabilities I often look for are XSS, IDORs, anything related to broken access control and SQL injections – those are my top three. In fact, I like to look for anything to do with injections. That’s what I've automated with the tools I developed.
On his most critical finds to date…
Difficult question because there are so many bugs! For example, I found a vulnerability that allowed me to access all the loyalty cards of a major retailer, so I could use the loyalty funds on those cards.
Another fairly critical vulnerability allowed me to access all the messaging systems of a major French retailer.
So there are many vulnerabilities! Unfortunately, I can’t choose just one, but that’s the charm of Bug Bounty.
On what he likes most about YesWeHack…
That's a very good question. In fact, I’ve tested all of the platforms that exist today, and I find that YesWeHack is by far the best in Europe in terms of its proximity to hunters; they are always open to discussion.
On his hobbies outside of hacking…
To be honest, I don’t have much time for other activities, but I do sometimes play tennis with my son, Ahmed. I play a bit of football when I have time. But that’s about it.
The thing is, a bug hunter absolutely must set aside time for themselves, for their mental health and all that.
I keep reminding people who are really into Bug Bounty hunting that they need to find a balance. In fact, it’s all part of a whole: if you're not in good health, things go wrong. You really need to find a balance between professional, mental and physical activities.
On his top tip for new hackers…
If I have one piece of advice to give, I always tell young people that their number one asset is time. You have time.
You have to spend your time on the platforms. Report initial vulnerabilities that are not going to be accepted.
For me, there are vulnerabilities for everyone. You just have to believe in yourself and work hard. There are training centres, so you have to get trained.
And I think today’s generation is really lucky because there are so many resources online. So I can’t name them all, but there’s the Dojo challenges at YesWeHack, there’s Hack The Box, there’s TryHackMe, and there are lots and lots of free online resources.
That’s why I say that all you need is a little time to develop your skills. Then I think you can go very far in Bug Bounty.
Interested in emulating rabhi? Register as a hunter on YesWeHack, sharpen your hacking skills on Dojo, or learn about the latest hacking tools and hacking techniques on our blog.



