The Vulnpocalypse Is Repricing the Bug Bounty Economy

The surge of AI-powered vulnerability reports is sending shockwaves through the bug bounty industry, threatening the livelihoods of independent researchers who rely on mid-tier vulnerabilities to make a living. As the “vulnpocalypse” reshapes the landscape, companies that run much of the bug bounty industry are struggling to keep up with the influx of reports and payouts.

The root cause of this issue is clear: large language models (LLMs) have unleashed a torrent of bug reports, forcing companies to triage and pay out on an unprecedented scale. Bug bounty operators like HackerOne, Zero Day Initiative (ZDI), and Bugcrowd are reporting dramatic increases in submission volume – with some seeing their rates double or even quintuple year-over-year.

But the impact is not just about volume; it’s also about quality. As more vulnerabilities are discovered, AI has enabled a glut of low-quality “slop” reports from those looking to make a quick buck or newer researchers who don’t know where to put their effort. This influx of slop reports is taking a toll on bug bounty operators, who must spend precious time and energy debunking false positives.

One consequence of this shift is that the price of many vulnerabilities is being driven down. While some researchers may welcome lower prices as a boon to the bug bounty ecosystem, others are sounding alarms about the implications for independent hunters. “I think the community is really nervous because one of the things that no one’s talking about yet is that the result is going to be driving the price of bugs down across the board,” says Dustin Childs, head of threat awareness for ZDI.

As the security research economy becomes a buyer’s market, mid-tier vulnerabilities – those worth roughly $10,000 to $50,000 – are likely to become scarce. In some cases, bounty amounts have already dropped significantly; for example, a full TCC/privacy bypass that used to pay around $30.5K may now be worth roughly $5K.

The AI effect is more than just a volume issue; it’s also changing the way companies approach bug bounty programs. Some are adopting AI-powered triaging to act as an initial filtering layer, while others – like Apple – have responded by instituting reporting pauses for users who repeatedly submit ineligible reports.

As the vulnpocalypse continues to reshape the bug bounty industry, one thing is clear: independent researchers must adapt quickly to survive. While lower prices may seem appealing at first glance, they could ultimately spell trouble for those who rely on mid-tier vulnerabilities to make a living. In this new landscape, it’s essential for security professionals to stay vigilant and adjust their strategies accordingly.

For readers who participate in bug bounty programs or rely on vulnerability research as part of their job, it’s crucial to reassess your approach to the field. Consider how you can diversify your skills and expertise to remain competitive in a market where prices are dropping and slop reports are on the rise. By staying proactive and adaptable, you’ll be better equipped to navigate the changing landscape of bug bounty economics.


Source: Dark Reading — 2026-08-28