Skip to main content
BTC / USDT107,400+2.19%ETH / USDT3,840+2.13%SOL / USDT182.40−1.99%BNB / USDT652.30+0.66%XRP / USDT2.2150+1.61%DOGE / USDT0.3850−1.79%TON / USDT5.240+2.34%AVAX / USDT42.60−2.07%LINK / USDT22.40+2.28%ADA / USDT1.0520−1.68%TRX / USDT0.3300+0.92%DOT / USDT8.420+2.93%BTC / USDT107,400+2.19%ETH / USDT3,840+2.13%SOL / USDT182.40−1.99%BNB / USDT652.30+0.66%XRP / USDT2.2150+1.61%DOGE / USDT0.3850−1.79%TON / USDT5.240+2.34%AVAX / USDT42.60−2.07%LINK / USDT22.40+2.28%ADA / USDT1.0520−1.68%TRX / USDT0.3300+0.92%DOT / USDT8.420+2.93%
Prezzi
cryptoJul 24, 2026, 10:40 AM

AI overwhelms bug bounty programs, forcing closures and payout cuts

AI-generated vulnerability reports are overwhelming cybersecurity firms, leading to program closures and reduced payouts for basic bugs. Verification has become the main bottleneck, with the market splitting between cheap automation and high-value exclusives.

The cybersecurity industry's long-standing bug bounty model is under strain as AI tools churn out vast numbers of vulnerability reports. Vendors are being flooded with low-quality submissions, forcing many to close their bounty programs or slash payouts for common flaws.

According to a new report from ForkLog, the core issue has shifted from discovering bugs to verifying them. The market is polarizing: automated scanning services offer cheap, bulk submissions, while a handful of researchers command million-dollar exclusives for critical zero-days.

The article warns that upcoming EU regulations could turn the flood of AI-generated reports into a corporate liability nightmare. The imbalance between discovery and validation threatens to undermine the entire incentive system.

Source: ForkLog