Bug bounty businesses bombarded with AI slop

Bug bounty businesses bombarded with AI slop

Bug bounty programs, which reward hackers for identifying software vulnerabilities, are facing significant challenges due to a surge in low-quality submissions generated by artificial intelligence. This influx of unreliable reports is prompting some companies to rethink their bug bounty strategies altogether. Bugcrowd, a notable platform in this field that serves clients including OpenAI, T-Mobile, and Motorola, reported that the volume of submissions it received skyrocketed over four times in just three weeks this past March. Unfortunately, the majority of these reports turned out to be invalid. In response to this growing issue, Curl, a popular tool for internet data transfer, halted its paid bug bounty program earlier this year, citing what it termed an “explosion in AI-generated slop reports” and a decline in submission quality. Experts in cybersecurity are observing that advancements in generative AI are transforming the landscape of bug bounty programs. While these tools enable seasoned researchers to identify vulnerabilities more efficiently, they also lower the entry barrier for newcomers, resulting in a deluge of automated or incorrect reports that companies must manage. Ross McKerchar, the chief information security officer at Sophos, emphasized that the increase in subpar AI-generated reports is rapidly becoming a pressing issue. He remarked, “Bug bounties are going to stay [but] they’re going to have to change.” Since their inception in the early 2000s, bug bounty programs have gained traction, with some offering substantial six-figure rewards for significant discoveries. For instance, Google’s initiative distributed $17 million last year, a sharp rise from $7.5 million in 2021, including a record individual payout of $605,000 in 2022 for a vulnerability found in its Android mobile operating system. McKerchar pointed out that the rise in poor-quality submissions stems from both novices attempting to find bugs and seasoned researchers who may be misled by AI agents during their investigations.

Sources : Ars Technica

Published On : May 18, 2026, 13:25

Science
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges

In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...

CNBC | Jul 25, 2026, 05:35
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
AI
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding

Prentis, a newly established AI research lab, is making waves in the tech industry as it prepares to raise $100 million ...

TechCrunch | Jul 25, 2026, 24:00
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding
AI
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage

In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...

Business Insider | Jul 25, 2026, 13:10
Shifting Focus: The Cost-Effectiveness of AI Models Takes Center Stage
AI
The Shift in Human Cognition: Embracing AI as a Collaborative Tool

As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...

Business Insider | Jul 25, 2026, 09:50
The Shift in Human Cognition: Embracing AI as a Collaborative Tool
View All News