Bug bounty businesses bombarded with AI slop

Ars Technica News

Summary

Bug bounty programs are being overwhelmed by a surge of low-quality AI-generated vulnerability reports, forcing platforms like HackerOne and Nextcloud to implement new filtering and validation measures. While the volume of submissions has jumped 76%, the rate of legitimate findings remains steady at 25%.

<p>Companies that pay hackers to find flaws in their software are being inundated with low-quality reports generated by AI, forcing some to suspend the programs altogether.</p> <p>Businesses that run “bug bounty” schemes have long relied on independent security researchers to spot vulnerabilities. But the rise of AI tools is now overwhelming them with spurious submissions.</p> <p>Bugcrowd, whose customers include OpenAI, T-Mobile, and Motorola, said the number of reports it received more than quadrupled over a three-week period in March, with most proving to be false.</p><p><a href="https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/">Read full article</a></p> <p><a href="https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 05/18/26, 03:48 PM

# Bug bounty businesses bombarded with AI slop Source: [https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/](https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-slop/) He added there was a “third cohort” of “experienced AI builders” who had developed automated “end\-to\-end scanning and submission systems” that were “creating absolute carnage\.” Curl’s creator, Daniel Stenberg, wrote in a blog post that the “never\-ending slop” had taken “a serious mental toll to manage and sometimes also a long time to debunk\.” Software group Nextcloud suspended its bug bounty program in April because of the “massive increase of low\-quality reports\.” It said it hoped to resume the program once it had found a way to filter submissions effectively\. The surge in AI\-generated reports comes as Anthropic last month launched Mythos, its new cyber AI model, which it says can find software flaws faster than humans\. Companies running bug bounty programs have started to introduce more stringent background checks to combat the problem, as well as building AI agents to triage submissions\. HackerOne, whose bug\-reporting platform serves Goldman Sachs, Google, and the US Department of Defense, said it had “introduced new agentic validation capabilities” this year to “help organizations manage high volumes of findings,” such as those generated by models like Mythos\. The company said submissions had jumped 76 percent in the year to March\. But it said the share of reports flagging legitimate vulnerabilities had remained steady over the past year at 25 percent\. HackerOne chief executive Kara Sprague said it had in recent weeks seen a rise in “higher quality” reports that had used AI\. She added that the rise in AI\-generated submissions was “not a strong reason to say we don’t want them” altogether, given that hackers were using the technology to spot more flaws\. Bugcrowd chief Dave Gerry said developments such as Anthropic’s Mythos would assist human bug bounty hunters, not replace them\. “AI is going to help with a lot of things but we’re never going to replace that human creativity,” he said\. *[© 2026 The Financial Times Ltd](https://www.ft.com/)\.[All rights reserved](https://www.ft.com/)\. Not to be redistributed, copied, or modified in any way\.*

Similar Articles

The AI Era Is Creating a Bug Hunting Arms Race

Wired

The article explores how AI-powered bug hunting is flooding vulnerability disclosure programs, changing the economics of bug bounties, and compressing disclosure timelines, while also benefiting attackers.

Introducing the OpenAI Safety Bug Bounty program

OpenAI Blog

OpenAI is launching a public Safety Bug Bounty program focused on identifying AI abuse and safety risks — including agentic risks, MCP vulnerabilities, and account integrity issues — complementing its existing Security Bug Bounty program. Researchers can submit issues that pose meaningful safety risks even if they don't qualify as traditional security vulnerabilities.