Bug bounty programs are being overwhelmed by a surge of low-quality AI-generated vulnerability reports, forcing platforms like HackerOne and Nextcloud to implement new filtering and validation measures. While the volume of submissions has jumped 76%, the rate of legitimate findings remains steady at 25%.
<p>Companies that pay hackers to find flaws in their software are being inundated with low-quality reports generated by AI, forcing some to suspend the programs altogether.</p>
<p>Businesses that run “bug bounty” schemes have long relied on independent security researchers to spot vulnerabilities. But the rise of AI tools is now overwhelming them with spurious submissions.</p>
<p>Bugcrowd, whose customers include OpenAI, T-Mobile, and Motorola, said the number of reports it received more than quadrupled over a three-week period in March, with most proving to be false.</p><p><a href="https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/">Read full article</a></p>
<p><a href="https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/#comments">Comments</a></p>
Turso is retiring its bug bounty program due to an overwhelming influx of low-quality, AI-generated submissions, highlighting the growing challenge of AI slop in open source maintenance.
The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.
Linus Torvalds says that AI-generated bug reports are flooding the Linux security mailing list with duplicates and useless submissions, making it unmanageable. He urges reporters to provide patches or validated findings instead of raw AI output, a view echoed by GitHub's security engineer.
OpenAI is launching a public Safety Bug Bounty program focused on identifying AI abuse and safety risks — including agentic risks, MCP vulnerabilities, and account integrity issues — complementing its existing Security Bug Bounty program. Researchers can submit issues that pose meaningful safety risks even if they don't qualify as traditional security vulnerabilities.
Researchers found that AI coding agents can be hijacked by following instructions hidden in external content like bug reports, achieving an 85% success rate. The vulnerability exploits the agents' automatic trust in input they did not generate.