The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge of AI-powered vulnerability reports is dramatically lowering bug bounty prices, particularly for mid-tier vulnerabilities worth $10,000 - $50,000. This is leading to increased submission volumes, extended triage and payout times, and a shift in the bug bounty market towards a ‘volume game’ where researchers increasingly rely on AI tools to find numerous lower-value vulnerabilities. Despite these challenges, the bug bounty ecosystem is not expected to disappear, but will likely evolve with researchers adapting to a market where vulnerability discovery is cheaper and more abundant.
The bug bounty industry is experiencing a significant shift driven by the proliferation of AI-powered vulnerability reports. The ‘vulnpocalypse,’ as it’s being termed, is causing a dramatic decrease in the value of mid-tier vulnerabilities – those typically worth $10,000 to $50,000 – which many independent researchers rely on for income. Multiple bug bounty operators report a doubling, and in some cases quadrupling, of submission volumes over the past year, with HackerOne, Bugcrowd, and ZDI all experiencing substantial increases.
Daniel Stenberg, creator of curl, cited a drop from 15% of submissions resulting in confirmed vulnerabilities in 2024 to under 5% by 2025, largely due to a glut of low-quality ‘slop’ reports generated by AI and inexperienced researchers. Apple has responded by instituting reporting pauses for users submitting ineligible reports.
Executives at HackerOne, Bugcrowd, and ZDI acknowledge that triage and payout times have extended, and they are implementing AI-powered triaging to assist human personnel. However, these efforts are not fully solving the problem.
Despite the challenges, the market for bug bounties isn't disappearing. Researchers are adapting, with 82% now utilizing AI tools to assist their workflows. Ashish Kunwar, a vulnerability researcher at GanaSec, uses AI heavily for code review and attack surface analysis, emphasizing the importance of maintaining human judgment for critical decisions like determining exploitability and impact.
Casey Ellis, co-founder of Bugcrowd, notes that the ecosystem is not static and that the ‘middle class’ of bug bounty researchers may simply look different by the time the current storm passes. The overall trend is towards a market where vulnerability discovery is cheaper and more abundant, requiring researchers to compete on volume and leverage AI to identify numerous lower-value findings. Aaron Portnoy, chief product officer at Mindgard, highlights that AI is accelerating software development, leading to the creation of poorly written software with inherent flaws, thus increasing the opportunities for researchers.
