Skip to main content
Live
Main content

Bug bounty programs buckle as AI-generated slop reports flood inboxes

Bugcrowd saw submissions quadruple in three weeks; Curl and Nextcloud suspended their programs as low-quality AI reports pile up.

Jaeden Schafer
Editor in Chief · · 5 min read
Bug bounty programs buckle as AI-generated slop reports flood inboxes

Corporate bug bounty programs are being overrun by AI-generated reports, and some operators have shut their schemes down rather than keep triaging the noise. Bugcrowd, whose customers include OpenAI, T-Mobile and Motorola, said the volume of submissions more than quadrupled over a three-week stretch in March 2026, with most turning out to be false. Curl, the data-transfer tool used across most of the internet, suspended its paid program in January, and software group Nextcloud followed in April.

HackerOne, the platform serving Goldman Sachs, Google and the US Department of Defense, logged a 76% jump in submissions in the year to March. The share of reports flagging legitimate vulnerabilities stayed flat at 25% over the same period — meaning three out of four submissions led nowhere.

The economics of bounty programs are shifting fast. Google's scheme disbursed $17 million last year, up from $7.5 million in 2021, and paid its largest individual reward of $605,000 in 2022 to a researcher who found a vulnerability in Android. Those payouts have always drawn opportunists, but generative AI has dropped the entry barrier far enough that anyone with a model and an API key can fire off plausible-looking reports at scale.

Key facts

  • 01Bugcrowd, which counts OpenAI, T-Mobile and Motorola as customers, saw reports more than quadruple over three weeks in March 2026.
  • 02HackerOne submissions jumped 76% in the year to March, but the share flagging legitimate vulnerabilities held at 25%.
  • 03Curl suspended its paid bug bounty program in January citing an explosion in AI slop; Nextcloud followed in April.
  • 04Google's bug bounty program paid out $17 million last year, up from $7.5 million in 2021, with a $605,000 individual record set in 2022.
  • 05Anthropic launched Mythos in April, a cyber AI model it says can find software flaws faster than humans.

Ross McKerchar, chief information security officer at Sophos, said the surge in poor-quality AI submissions was "quickly becoming a major problem." He identified three groups behind it: first-time amateurs leaning on AI tools, established researchers being "led on" by their agents, and a third cohort of experienced AI builders who have wired up end-to-end automated scanning and submission pipelines. That last group, McKerchar said, is "creating absolute carnage."

HackerOne logged a 76% jump in submissions in the year to March, yet the share flagging real vulnerabilities stayed flat at 25%.
Jaeden Schafer

Curl's creator Daniel Stenberg wrote that the never-ending slop had taken "a serious mental toll to manage and sometimes also a long time to debunk." Nextcloud said it hoped to resume its program once it could filter submissions effectively. Both cases point to the same operational problem: the cost of reviewing a report is borne by the company, while the cost of generating one has collapsed to near zero.

The timing is awkward for AI labs that are themselves shipping security-focused models. Anthropic launched Mythos last month, pitching it as a cyber AI model that can find software flaws faster than humans. Tools like Mythos can in principle help legitimate researchers — but they also feed the same automated submission pipelines that are clogging triage queues at Bugcrowd and HackerOne.

Platforms are responding by building their own AI to filter incoming AI. HackerOne said it had "introduced new agentic validation capabilities this year to help organizations manage high volumes of findings," specifically citing models like Mythos. Bugcrowd has tightened background checks on submitters. The arms race has effectively moved one layer up the stack — from finding bugs to verifying that the finder is real.

HackerOne chief executive Kara Sprague said the company had seen a recent uptick in higher-quality reports that used AI, and argued the rise in AI-generated submissions was "not a strong reason to say we don't want them" altogether, given that hackers were using the technology to spot more flaws. Bugcrobwd's Dave Gerry echoed the point on Mythos: "AI is going to help with a lot of things but we're never going to replace that human creativity."

Related · from this week
AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates
Jaeden Schafer · 5 min read →

The counter-case is harder to dismiss. A 25% legitimate-vulnerability rate against a 76% volume increase means HackerOne's reviewers are processing far more reports per real finding than a year ago. If that ratio drifts further — and the three-week quadrupling at Bugcrowd suggests it can — more programs will follow Curl and Nextcloud into temporary suspension. McKerchar's framing was blunter: "Bug bounties are going to stay [but] they're going to have to change."

The bigger signal for the AI security market is that triage, not detection, is now the bottleneck. The labs selling AI-powered vulnerability finders are creating demand for AI-powered vulnerability filters, and HackerOne's agentic validation push is the first commercial product built explicitly around that loop. Expect every major bounty platform to ship a similar layer within the next year, and expect the next wave of security-AI funding to flow toward the verification side of the pipeline rather than the discovery side. The economics of crowdsourced security only work if the signal-to-noise ratio holds — and right now it isn't.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates
Security

AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates

Google and Apple face 2–10x more bug submissions; researchers report tripled output, forcing bounty programs to rebalance economics.

Jaeden Schafer5 min read
Lawsuit seeks to force Trump administration to reveal AI safety review rules
Security

Lawsuit seeks to force Trump administration to reveal AI safety review rules

Protect Democracy sues four federal agencies for the unclassified framework governing which frontier AI models get released.

Jaeden Schafer5 min read
Anthropic logo
Security

US lifts export curbs on Anthropic's Claude Fable 5 and Mythos 5

Fable 5 goes global and Mythos 5 access returns for US users after three weeks of safety testing and tighter jailbreak defenses.

Jaeden Schafer5 min read