In 2019, the author began their journey into cybersecurity by attending Ekoparty, where they were introduced to the concept of bug bounty hunting, initially assuming it required highly specialized skills. Over time, they learned that success in bug bounty hunting doesn't require being an expert hacker but understanding one vulnerability type thoroughly and searching for it manually in various environments. They emphasize a manual-driven approach, suggesting the use of platforms like PortSwigger labs and HackTheBox for practice, along with reading and taking detailed notes on vulnerabilities. The author shares their experience of discovering an HTML Email Injection vulnerability, which earned them a $200 reward on Bugcrowd, highlighting the importance of understanding how an attacker might exploit vulnerabilities. They encourage aspiring hackers to join bug bounty programs, practice regularly, and engage with communities for mentorship, emphasizing that the monetary rewards are secondary to gaining skills and experience.