July 29, 2025

Watch Now - The Innovation Circuit: The Breaker and the Builder - Million Dollar Bug Bounties with Ron Chan (Nova Security)

By

Theta

Watch Now - The Innovation Circuit: The Breaker and the Builder - Million Dollar Bug Bounties with Ron Chan (Nova Security)

Ron Chan, a prolific bug bounty hunter, was featured in Forbes as one of the elite few to surpass $1 million in rewards from ethical hacking programs. Throughout his career, he's made high-impact submissions to platforms such as Uber, GitLab, Yahoo, Google, PayPal and Spotify. Fast forward to 2025, Ron uses his exceptional skill set to help New Zealand organisations identify and address security vulnerabilities - now serving as Principal Consultant at Nova Security.

In today's episode, we discuss the landscape of penetration testing and bug bounty programmes - and how the "builders" (product teams and technology creators) can work effectively with the "breakers" (penetration testers and ethical hackers like Ron) to create more secure digital solutions.

Panellists:

Ron Chan, Principal Security Consultant at Nova Security

Andrew Taylor, Head of Product at Theta

Moderator: 

Liz Knight, Head of Cyber Security at Theta

Listen wherever you get your podcasts or watch the full discussion below ⬇️

Takeaways

  • Ron Chan’s Journey: Ron became one of the first ethical hackers to surpass $1M in bug bounty payouts by finding and reporting vulnerabilities.
  • Bug Bounty Landscape: The field has grown with AI making bug hunting easier, but competition is rising; opportunities remain for skilled hackers.
  • Nova Security: Founded to help New Zealand companies improve cyber security through advanced penetration testing and other services.
  • Critical Vulnerabilities: Recent findings include a telecom flaw enabling SIM card takeovers and AI-related risks from poorly configured MCP servers.
  • Theta’s Approach: Theta integrates secure coding, peer reviews, automated scanning. Products like Glasstrail are used for ongoing vulnerability management.
  • Collaboration & Communication: Effective security depends on strong communication between developers and pen testers, with quick responses to critical issues.
  • Top Security Advice: Ron recommends attack surface management tools (e.g. Glasstrail), while Andrew stresses staying ahead of evolving threats, especially in AI.
  • Chapters

    01:00 Ron's Route to Becoming One of The First Millionaire Bug Bounty Hunters

    02:28 What Does The Bug Bounty Scene Look Like Today?

    03:58 Establishing Nova Security And Its Mission

    04:48 Pen Testing When Developing Products

    05:40 Recent Vulnerabilities Discovered

    09:04 Balancing Rapid Product Development With Managing Vulnerabilities

    11:48 The Breaker and The Builder: What Makes For a Productive Relationship?

    13:14 Beyond Pen Testing: Community Support and Security Tools

    16:17 One Thing Businesses Should do Today to be More Secure

    Resources

    Forbes: How To Make $1 Million From Hacking: Meet Six Hacker Millionaires

    Nova Security

    Nova Security: The 'S' in MCP Stands For Security - Part 2

    Glasstrail - Attack Surface Management Tool

    EVA Check-in - Sign-in, Safety & Compliance Tools for People-First Workplaces

    Helpfruit - The AI Agent for Every Customer Ask

    Theta Assist - The Power of ChatGPT Customised For Your Business

    Penetration testing services

    Talk to our team