Tony Wang7 min readGitHub's Security Researchers Have the Steepest Follower Curve of Any Specialty We've Measured
We re-sliced our GitHub census by the security tag: the US leads (unlike AI/ML), and followers skew further from GitHub's norm than any domain we've checked.
We've now sliced Crawlora's 972,576-profile GitHub Users census two ways: by the ml-ai interest-domain tag, where India surprisingly led the US, and now by security — 6,829 profiles tagged as security-focused based on repo topics and bio text. The geography reverts to the expected order, but the follower economics get more extreme, not less.
Geography reverts to form — the US leads, unlike AI/ML
Where our ml-ai cut found India ahead of the US, security researchers put the US back in front:
By city, Bengaluru still tops the list at 67 — as it does in every cut of this dataset we've run — but London (61) and New York (56) follow closely, well ahead of San Francisco (47) and New Delhi (46). Lagos (27) and Nairobi (24) place higher here than in either the overall census or the ml-ai cut, a small signal of a growing African security-research community.
The steepest follower curve of any specialty we've measured
This is the real finding. Compare the follower-tier distribution across all three populations we've now measured from the same dataset:
86.6% of security-tagged developers sit in the nano tier, versus 90.5% for ml-ai and 95.3% for GitHub overall — the largest gap from the baseline of any domain we've sliced. The micro tier (100-999 followers) holds 11.3% of security researchers, more than double the overall population's 4.2%. Vulnerability disclosure, CTF wins, conference talks and open-source security tooling appear to build public followings even more reliably than AI/ML work does, at least among developers who tag themselves this way.
Show the top 10 most-followed security-tagged developers
| Login | Name | Followers | Known for |
|---|---|---|---|
| mathiasbynens | Mathias Bynens | 12,956 | Google · web standards, JS/security |
| alex | Alex Gaynor | 10,637 | Anthropic · Python/Rust security work |
| benbalter | Ben Balter | 10,328 | GitHub · policy, trust & safety |
| TheOfficialFloW | Andy Nguyen | 5,685 | PS Vita jailbreak, console security research |
| insidegui | Guilherme Rambo | 4,914 | macOS/iOS security research |
| mrexodia | Duncan Ogilvie | 3,704 | Creator of x64dbg |
| vanhauser-thc | van Hauser | 3,667 | The Hacker's Choice · creator of THC-Hydra |
| D4Vinci | Karim Shoair | 3,452 | Security researcher, Egypt |
| thewhiteh4t | Lohitya Pushkar | 3,425 | Security researcher, UK |
| Mr-xn | 东方有鱼名为咸 | 3,311 | InfoSec researcher, China |
Unlike GitHub's overall top-followed list — or even the ml-ai cut, where corporate-affiliated researchers dominate — several names here are independent tool authors: Duncan Ogilvie built the widely-used x64dbg debugger; van Hauser created THC-Hydra, one of the most common password-auditing tools in penetration testing; Andy Nguyen is known for console-hacking work (PS Vita, PS4). Security research culture rewards a released tool or public disclosure with followers in a way that seems less tied to which company you work for.
Named employers mix big tech with security-only vendors
The named-employer list for security-tagged developers pulls in the same big-tech names as other cuts, but with security-specific vendors appearing that don't show up anywhere else in this dataset:
Microsoft and Google lead, consistent with their scale, but Palo Alto Networks, Nord Security, SpecterOps, Trail of Bits, ProjectDiscovery and CrashAppSec appear nowhere in our GitHub-overall or ml-ai employer lists — a distinct, identifiable security-vendor fingerprint that only shows up once you filter for this specific population.
What this means for security hiring, sponsorship, and bug-bounty programs
For security recruiting, the geography here is closer to conventional wisdom than the ml-ai cut was — the US leads — but the underlying reachability math is identical: this population is 2.6x more likely to expose a contact channel and 2.8x more likely to mark itself open to hire than GitHub's general population. For bug-bounty and vulnerability-disclosure programs, the follower-tier skew suggests that a security researcher's GitHub following is a genuinely useful signal of standing in the field, more so than in most other specialties. And for security-tooling vendors doing developer marketing, the named-employer list is a ready-made account map of who else is already investing in this space.
Query the GitHub Users dataset by interest domain
Filter 972,576 enriched developer profiles by domain (security, ml-ai, web, devops and more), geography, company or influence tier — over one REST API.
Frequently asked questions
Which country has the most security researchers on GitHub?
The United States, with 870 geo-resolved developers tagged security in Crawlora's GitHub Users census, ahead of India (711). This is the reverse of the ml-ai cut of the same dataset, where India led the US 4,810 to 3,536.
Are security researchers more followed than other GitHub developers?
Yes, and by the widest margin of any domain we've measured. Only 86.6% of security-tagged developers sit in the lowest (nano, under 100 followers) tier, versus 90.5% for ml-ai-tagged developers and 95.3% for GitHub overall - the steepest deviation from the platform-wide baseline we've found.
Are GitHub security researchers easier to reach and recruit than other developers?
Yes - 55.8% expose a public contact channel (versus 21.2% of GitHub overall) and 21.1% mark themselves open to hire (versus 7.5% overall), almost identical uplift to the ml-ai cut of the same dataset.
Who are the most-followed security researchers on GitHub?
Independent tool authors and researchers dominate the top of this list: Duncan Ogilvie (creator of the x64dbg debugger), van Hauser (creator of THC-Hydra), and Andy Nguyen (known for PS Vita and console-hacking research), alongside corporate-affiliated researchers like Mathias Bynens (Google), Alex Gaynor (Anthropic) and Ben Balter (GitHub).