Turso Ends Its Bug Bounty Program
Key point
Turso has ended its bug bounty program due to a flood of low-quality, AI-generated PRs.
Details
Turso's bug bounty program, which paid $1,000 for demonstrated data corruption bugs, has ended after about a year.
The main cause was an explosion of low-quality AI-generated PRs (Pull Requests). Once the reward was on the line, low-quality submissions aimed purely at collecting the bounty poured in—people using LLMs to claim meaningless bugs, manually corrupting database headers, and deliberately inserting out-of-bound access into the source code.
As a result, maintainers had to waste days dealing with false claims and disputes generated by AI instead of finding actual bugs. Turso responded by introducing a vouching system to block bots, but it proved insufficient to stop the automated attacks, as bots requested manual review or repeatedly submitted similar PRs.
Rather than shutting down the project, Turso decided to remove the monetary incentive in order to preserve its open-source contribution ecosystem. This points to new operational challenges facing open-source governance in the era of generative AI.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.