XOOMAR
Young ethical hacker at a laptop with glowing security shields and encrypted data around a house silhouette
CybersecurityJune 21, 2026· 8 min read· By XOOMAR

Bug Bounties Bought This Ethical Hacker a House at 21

Share
Updated on September 13, 2026

Isira Adithya bought his first house at 21 with money earned from bug bounties, after starting out as an 11-year-old building LED bulbs and selling them to teachers.

XOOMAR Intelligence

Analyst Take

65/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness99Source Trust85Factual Grounding90Signal Cluster20

That arc, detailed by SecurityWeek, is more than a feel-good hacker profile. It shows how ethical hacking has become a real career path for unusually driven young researchers, while also exposing how self-directed, uneven, and hard to replicate that path can be.

Adithya’s story is compelling because it compresses a full cybersecurity career ladder into a teenager’s timeline: hardware tinkering, game modification, Wi-Fi experiments, CTF challenges, XSS labs, bug bounty platforms, a computer security degree, then major life purchases funded by vulnerability research.

“Hackers are people who refuse to take technology at face value. They probe, test, and dismantle to understand what’s inside and how it behaves.”

That quote is the thesis. Adithya didn’t enter security through a corporate training program. He entered by refusing to accept systems as finished objects.

Isira Adithya Turned Childhood Tinkering Into a Bug Bounty Career

Adithya was gifted a laptop by his parents after passing a scholarship exam at age 10. By 11, he was learning how to hack computer games. Before that, he had already broken a DVD player while trying to reroute audio output to custom speakers.

That matters. Security talent often starts with physical curiosity, not compliance. Adithya wanted to know how cars worked, how helicopters flew, and how electronic equipment behaved. At 12, he built a small four-motor drone that eventually hovered after repeated failed attempts.

His early work with LED bulbs, custom speakers, boot logos, phone operating systems, and offline PC games points to the same instinct: change the intended behavior. Not steal. Not sabotage. Change.

XOOMAR analysis: that distinction is central to ethical hacking. The technical impulse can look similar at the beginning, probing, dismantling, bypassing, but the direction of travel depends on incentives, norms, and legal channels. Adithya’s later discovery of bug bounties gave that curiosity a legitimate market.


Between ages 12 and 14, Adithya explored Wi-Fi hacking with help from an older family guest who “knew about computers.” Because internet access was expensive, he asked that guest to download YouTube videos about Wi-Fi hacking. He studied them repeatedly.

Then came the challenge: hack into the guest’s mobile hotspot. Adithya says he ran a brute force attack for about two days before cracking the password.

“The adrenaline rush was unforgettable.”

That sentence explains both the opportunity and the risk. The excitement of technical success can push a young hacker in several directions. In Adithya’s case, the decisive redirect came around 2018 to 2019, when he discovered videos about bug bounty hunting.

“The idea that you could legally hack real-world applications, get paid and be recognized, felt like a dream,” he told SecurityWeek. His first bounty did not arrive immediately. It took until April 2021, when he was 16.

That two-year gap is the part aspiring hackers should read twice. The headline outcome is a house at 21. The underlying story is years of unpaid learning, repeated practice, and a move from curiosity to disciplined reporting.

Bug Bounty Money Changed the Economics, But This Is Not a Beginner Template

The source does not disclose Adithya’s total bug bounty earnings, individual payout sizes, or the companies involved. That matters because the numbers behind bug bounty success are often the difference between a career and a hobby.

What SecurityWeek does verify is still striking:

Milestone Age or date Source-backed detail
Gifted first laptop 10 Parents gave it after he passed a scholarship exam
Built and sold LED bulbs 11 Sold them to teachers
Built a four-motor drone 12 It eventually hovered
Ranked in TryHackMe CTFs 15 Among the top ten in Sri Lanka
First bug bounty April 2021, age 16 Began earning from legal vulnerability research
Bought first car After bounty earnings Funded from bug bounty income
Graduated Age not specified First class honours degree from University of Plymouth via NSBM Green University
Bought first house 21 Funded by bug bounty work

XOOMAR analysis: buying a house with bug bounty earnings is an exceptional result, not a normal starting outcome. The useful lesson is not “bug bounties make teenagers rich.” It is that verified vulnerability work can become economically meaningful when paired with persistence, technical range, and a reputation for operating inside legal boundaries.

The company-side logic is also clear from the source. Bug bounties help businesses find and fix bugs before black hats use them. The social logic is just as important: they reward hackers for using the same curiosity in a lawful way.

For a different kind of vulnerability story, where an enterprise flaw was already being hit by attackers, see XOOMAR’s coverage of Attackers Hit Cisco SD-WAN Flaw Cisco Says It Found First. Adithya’s profile sits on the other side of that same security equation: find flaws early, report them cleanly, and get rewarded before damage follows.


Universities and Hiring Managers Should Read the Signal in Adithya’s Timeline

Adithya enrolled at NSBM Green University in Sri Lanka because he wanted a computer security degree. Through NSBM’s transnational education partnership with the University of Plymouth in the UK, he completed the Plymouth degree course while studying in Sri Lanka. He graduated with first class honours.

The degree matters. So does the work he had already done before and during it.

By 15, he was doing TryHackMe CTF challenges and ranked among the top ten in Sri Lanka. A year later, he solved his first XSS challenge on Intigriti and moved into serious bounty hunting. Those are practical signals. They show applied curiosity, persistence, and comfort with real testing environments.

XOOMAR analysis: hiring managers who screen only for degrees, certifications, or years in a formal role will miss people like this. A verified body of security work can reveal ability earlier than a conventional résumé. The reverse is also true: students should treat labs, writeups, CTFs, responsible disclosure, and bug bounty reports as career assets, not side quests.

The lesson is not anti-university. Adithya used bounty income to fund education and still pursued a formal computer security degree. The stronger point is that education and hands-on research compounded each other.

Ethical Hacking Has Professionalized, But the Core Instinct Hasn’t Changed

SecurityWeek describes Adithya as a “second generation hacker.” The first generation often found hacking through the economic need to access expensive internet and connect with like-minded people. Adithya’s route was different. His motive was not early profit. It was curiosity, control, and the satisfaction of making systems behave differently.

Bug bounties gave that instinct a market.

That market rewards more than technical cleverness. Researchers need legal discipline. They need enough communication skill to explain what they found. They need restraint, because the same knowledge can be used for security research or malicious gain.

Adithya’s own definition captures the split cleanly: hackers probe and dismantle systems to understand them, and that can support “security research, building better systems, or, in the wrong hands, for malicious gain.”

XOOMAR analysis: the industry’s job is to make the ethical path more attractive than the malicious one. Bug bounties are one mechanism. Education is another. Public recognition matters too, especially for young researchers outside traditional tech hubs.

The Next Isira Adithya Will Need Curiosity Plus Professional Proof

Adithya’s path points to a future where serious cyber careers can start early. Not because every teenager can buy a house from bug bounties, but because the tools, platforms, and legal routes now exist for talented researchers to build proof before they enter the workforce.

The next winners will likely look a lot like him in one respect: they’ll start by taking systems apart mentally before anyone gives them permission or a job title. But curiosity won’t be enough. They’ll need boundaries, documentation, repeatable methods, and the patience to keep learning for years before the rewards become visible.

The evidence to watch is practical. More students building public proof through CTFs, bounty platforms, responsible disclosure, and security writeups would strengthen the Adithya thesis. If those channels fail to reward good-faith research clearly, the industry will keep depending on rare outliers instead of building a wider ethical hacking pipeline.

Key Takeaways

  • Adithya’s path shows ethical hacking can become a serious career at a young age.
  • His story highlights how curiosity and hands-on tinkering can develop into cybersecurity expertise.
  • The profile also shows that self-taught hacker career paths can be uneven and hard to replicate.

Isira Adithya's Early Cybersecurity Timeline

Gifted laptop
age10
Learning to hack games
age11
Built four-motor drone
age12
Bought first house
age21
XOOMAR

Written by

XOOMAR

Data desk

XOOMAR is a capital markets software and data company. Every brief on this site starts from a dataset the company collects itself from primary sources (CFTC, SEC EDGAR, FINRA, the Federal Reserve, exchange APIs) and names the numbers it is built on, with a link to the data page so you can check them. Briefs are reviewed before they go out and corrected in place when the data is revised.

Related Articles

AI security scanner overwhelming a researcher with vulnerability alerts behind a glowing digital shield.Cybersecurity

AI Crushes Bug Bounty Pricing as Flaw Hunting Gets Cheap

AI won't kill security research. It will crush the old bug bounty model by making flaw discovery cheap and triage painfully scarce.

Jun 15, 20268 min
Cybersecurity investigators examine encrypted files near a European institution under a dark digital threat.Cybersecurity

ShinyHunters Breach Claim Jolts Council of Europe

ShinyHunters claims it stole 429,000 Council of Europe files. Officials are investigating and haven't confirmed a breach.

Jun 15, 20265 min
Enterprise server shielded from red cyberattack streams, symbolizing critical Ivanti Sentry flaws.Cybersecurity

Root Access Bug Throws Ivanti Sentry Into Patch Panic

Ivanti patched two critical Sentry flaws, including a CVSS 10 bug that can give remote attackers root command execution.

Jun 10, 20265 min
Dark cybersecurity scene showing a Mac-like laptop, fake prompt, mounted disk, locks, and stolen data streams.Cybersecurity

Fake CAPTCHA Turns macOS ClickFix Attack Into Mac Heist

A fake CAPTCHA pushes Mac users into Terminal, launching AMOS to steal browser, wallet, Keychain and app data.

Jun 23, 20267 min
Cyber breach at electronics supplier shown with factory, servers, shields, locks, and stolen data shards.Cybersecurity

Tata Electronics Data Breach Exposes Apple, Tesla Risk

Tata confirmed a breach after hackers claimed 204,341 Apple and Tesla-linked files, raising fresh supplier-risk alarms.

Jun 23, 20269 min
Close-up of a cryptocurrency market graph focusing on BNB price and volume trends over time.Trading

Bitwise Bitcoin ETF Added 119.37 BTC ($9.69 Million) on Friday

Bitwise’s Bitcoin ETF added $9.7 million in BTC on Friday, a modest inflow during its ongoing recovery phase after a period of heavy outflows.

Sep 19, 20266 min
Colorful trading charts showing cryptocurrency market trends on a computer screen.Trading

Leveraged Funds Trim Record Bitcoin Short Position by 1,538 Contracts

Leveraged funds have started to unwind their record bearish bet on Bitcoin, trimming their net short position by over 1,500 contracts in the latest CFTC data.

Sep 18, 20266 min
Detailed financial trading screen with colorful charts and data representing market fluctuations.Trading

Bitwise fund adds 0 coins on Thursday as iShares snapshot remains static

The Bitwise Bitcoin ETF recorded zero net inflows on Thursday, a pause in its volatile history of a $281 million washout and a $238 million single-day recovery.

Sep 18, 20266 min
Close-up of a cryptocurrency market graph focusing on BNB price and volume trends over time.Trading

BITB Dips $12.36 Million on a Lumpy Recovery

The Bitwise Bitcoin ETF saw a $12.36 million outflow, cooling off after its biggest-ever $237 million inflow and marking a volatile, multi-phase trajectory.

Sep 18, 20266 min
Vibrant digital chart showcasing cryptocurrency market trends with candlestick patterns.Trading

Bitwise BITB Bitcoin Holdings Hit Zero-Day Print on Tuesday

Bitwise's BITB Bitcoin ETF recorded a rare zero-day print, marking a pause in flows after a volatile cycle that saw a $280 million outflow and a peak of over 38

Sep 16, 20266 min

Don't miss the signal

One email a week on what changed in the data: positioning, flows, funding and the calendar.

Free forever. No spam. Unsubscribe anytime.