DEF CON 34: How AI Is Changing Bug Bounty
Key point
AI is transforming Bug Bounty operations by simultaneously increasing vulnerability submission volumes and verification burdens.
Details
At the "Navigating AI-Assisted Submissions" panel in the DEF CON 34 Bug Bounty Village, representatives from HackerOne, Synack, Bugcrowd, Intigriti, and YesWeHack assessed AI not as a problem, but as a new environment that the Bug Bounty industry must adapt to.
While AI has accelerated the speed of vulnerability discovery, verification and remediation still proceed at human speed, increasing the burden and burnout of triage teams.
- Total submission volume increased by approximately 2x year-over-year.
- The valid report ratio did not change significantly, but the absolute number of valid reports increased.
- Confirmed Critical vulnerabilities increased by approximately 3x in recent months.
- HackerOne reported a 76% increase in submissions over 12 months, while Bugcrowd explained that their triage queue increased by 334% in just three weeks.
Low-quality AI-related submissions fall into three main categories.
- Hallucinated reports that plausibly describe non-existent vulnerabilities
- Excessively long reports where valid vulnerabilities are buried under excessive information
- Automated submission reports where inexperienced users connect AI agents to programs to submit in bulk
While large platforms maintain their valid report ratios despite increased submission volumes, small open-source projects are taking a bigger hit. curl suspended its Bug Bounty program in January 2026 after its valid report ratio dropped from approximately 1 in 6 to 1 in 20–30.
The panel pointed out that researchers should verify reproducibility before submitting, and that platforms and program operators should specifically disclose the types of vulnerabilities they want and the Out of Scope boundaries. Rewards for Low and Medium vulnerabilities that AI can easily find may decrease, and Google has changed its policy to eliminate monetary rewards and credits for lower tiers of the OSS VRP, focusing instead on vulnerabilities that are difficult for AI to find.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.