Skip to main content
Live
Main content

AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates

Google and Apple face 2–10x more bug submissions; researchers report tripled output, forcing bounty programs to rebalance economics.

Jaeden Schafer
Editor in Chief · · 5 min read
AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates

AI-powered bug hunting has tripled researcher output and forced companies like Google to overhaul vulnerability reward programs as both ethical hackers and criminal actors accelerate exploit discovery. Independent researcher Joseph Thacker reports submitting three times more bugs this year than last, and estimates Google will spend 2–10x more on bug payouts in 2026. Apple's top bounty reward climbed from $200,000 in 2016 to $2 million last year as the economics of vulnerability disclosure shift rapidly.

Google overhauled its Vulnerability Reward Programs for Chrome and Android in April, lowering payouts for some bug classes while raising others. The company framed the changes as a response to the AI-driven surge in submissions, aiming to reward the most challenging and impactful vulnerabilities. Tech giants can absorb the increased payout volume, but smaller organizations face mounting pressure as the flood of AI-assisted findings strains disclosure processes and patch cycles.

I've probably submitted three times more bugs than I did last year at this time—I would suspect that a company like Google is going to spend two to 10 times as much on bug payouts as they did last year
Joseph Thacker, Independent security researcher

The shift is compressing disclosure timelines industry-wide. The 90-day responsible disclosure standard emerged when bug discovery was rare and exploit development slow — conditions no longer true. AI models now autonomously identify vulnerabilities and generate working exploits, forcing organizations to patch faster while risking deployment errors and outages at scale.

Key facts

  • 01Independent researchers report tripled bug submission rates year-over-year as AI accelerates vulnerability discovery.
  • 02Google expects to pay 2–10x more in bug bounties this year and overhauled its Chrome and Android programs in April.
  • 03Apple's top bug bounty reward climbed from $200,000 in 2016 to $2 million last year.
  • 04Google observed criminal actors using AI to develop a zero-day exploit for an open source administration platform earlier this month.
  • 05Curl ended its HackerOne bug bounty in January after being flooded with low-quality AI-generated submissions.

Attackers are adopting the same tools. Google researchers observed prominent cybercrime actors using AI to develop a zero-day exploit targeting an open source system administration platform earlier this month. The exploit bypassed two-factor authentication; Google notified the developer, who issued a fix. John Hultquist, chief analyst at Google Threat Intelligence Group, called the incident the first confirmed case of criminals using AI to discover novel vulnerabilities. Zero-day use by criminal actors has historically been limited to the most sophisticated groups, but AI lowers the barrier.

The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines.
Himanshu Anand, Security researcher

The quality of AI-assisted bug reports has improved sharply after an initial wave of low-grade submissions. Curl ended its HackerOne bounty program in January after being overwhelmed by fabricated AI-generated problems. Linux creator Linus Torvalds wrote last week that the Linux security mailing list had become almost entirely unmanageable due to high-volume duplicate AI reports. But Curl founder Daniel Stenberg reported in April that the project now receives an ever-increasing volume of genuinely high-quality security reports, almost all done with the help of AI, submitted at a never-before-seen frequency.

Bug bounty hunters face uncertain economics as the low-hanging fruit disappears. Researchers who developed AI-assisted workflows early are seeing payout gains, but the market will likely rebalance as more bugs get discovered and fixed. Jonathan Dunn, a cardiologist and bug bounty hunter, argues that top-tier researchers with specialized skills will continue finding payouts from large companies, but public infrastructure and critical systems that lack formal bounty programs risk being neglected.

Anthropic launched a HackerOne bug bounty earlier this month for findings on its own systems and Claude AI models, joining the institutions competing for researcher attention. Alex Zenla, CTO of cloud security firm Edera, notes that AI-assisted bug hunting still requires significant human time despite changing industry dynamics.

The long-term defense may require architectural shifts rather than faster patching. Longtime security engineer Niels Provos argues that organizations cannot patch their way out of the accelerated discovery cycle. Instead, they need to build infrastructure that makes entire classes of bugs irrelevant or significantly less exploitable in practice.

Related · from this week
Claude shared chats and Artifacts surfaced in Google search results
Jaeden Schafer · 4 min read →

The current bounty model rewards individual findings, but the AI era may demand systemic defenses that eliminate vulnerability categories before they can be exploited. Researchers are already competing against both criminal actors and other ethical hackers using the same AI tools, compressing the window between discovery and weaponization to days or hours. The question is whether patch cycles and structural defenses can keep pace with exploit development that now runs at machine speed.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Claude shared chats and Artifacts surfaced in Google search results

Anthropic's share-link feature exposed conversations containing medical records, children's contact details, and internal company documents.

Jaeden Schafer4 min read
Google logo
Analysis

Gemini's Spark, Daily Brief, and chat sprawl expose an AI branding problem

Google's Gemini app now houses three separately branded features — a pattern Anthropic and OpenAI repeat, and Apple deliberately avoids.

Jaeden Schafer4 min read
Anthropic logo
Analysis

University of Washington student ships interactive map of AI data center policy

Isabelle Reksopuro's tool uses Claude to refresh four times daily, charting buildouts from The Dalles to Texas.

Jaeden Schafer4 min read