Raphaël Arrouas

Independent Ethical Hacker

Biography.

Raphaël Arrouas (Xel) is a security engineer specializing in offensive security.
Following positions as a penetration tester, he has been working as the first full-time bug bounty hunter in Switzerland starting from 2019, and was referenced by the Swiss Federal Council in their 2023 report promoting ethical hacking. He has reported a few thousand vulnerabilities to companies and organizations around the world, and has been ranked #1 on Bug Bounty Switzerland (all-time ranking in 2022, 2023, 2024), #2 on YesWeHack (current all-time ranking) and #5 on Yogosha (yearly ranking in 2025). He has participated to the 2024 HackerOne Ambassador World Cup with the French team. In addition to bug hunting, he has volunteered in expert consultations on the Digital Emblem project for the International Red Cross Committee, a project in International Humanitarian Law that aims to translate the Geneva Convention to digital warfare.

Talk.

Navigating the Maze: A Hunter's guide to successful Bug Bounty programs

The transition from classic security audits to Bug Bounty is often fraught with misplaced expectations and design pitfalls. This talk aims to navigate the practical realities of bug hunting, and how to turn a flood of reports (or lack thereof) into actionable intelligence. I will begin by defining the Bug Bounty ecosystem, identifying its key players and their motivations, while clarifying the fundamental differences between a bug bounty program and a traditional penetration test. I will share insights about what the life of a bug hunter really is, and the challenges to overcome to stay ahead in the race. We will then see common pitfalls and misconceptions that can arise when designing a bug bounty program, as they significantly differ from traditional quality testing. In particular, we will address the gap between a company’s perceived exposure and the intricate maze uncovered by hunters. I will provide a roadmap to launch a successful program that turns hackers into long-term partners, helps gain valuable insights for companies, and fosters security champions. We will conclude with a forward-looking perspective on the current state of bug bounty, and why Artificial Intelligence, while transformative, will not “solve” security but may instead introduce a new frontier of complex logic vulnerabilities.

Get in Touch

We would love to speak with you.
Feel free to reach out using the below details.