Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ireland will be united, says Gordon Brown | Northern Ireland

    August 29, 2026

    Glencore threatened with $1.4bn lawsuit from embattled trader Radiant

    August 29, 2026

    Brave’s browser one-ups Chrome with its new support for email aliases

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ireland will be united, says Gordon Brown | Northern Ireland
    • Glencore threatened with $1.4bn lawsuit from embattled trader Radiant
    • Brave’s browser one-ups Chrome with its new support for email aliases
    • The Vulnpocalypse Is Repricing the Bug Bounty Economy
    • Fed Chair Warsh Calls AI a ‘Hinge Point in History’—4 Key Things He Said
    • Failed environmental safeguards leave coastal Bangladesh facing coal pollution
    • Seeing red when cyclists decide not to stop at traffic lights | Cycling
    • Did Ron Howard write letter about being liberal? Here’s the truth
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    The Vulnpocalypse Is Repricing the Bug Bounty Economy

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.

    It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.

    Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”

    Related:Chinese Routers Sold Worldwide Contain Backdoors

    Ashish Kunwar, vulnerability researcher at GanaSec and a long-time bug bounty researcher, tells Dark Reading that, “Since last year, the entire pipeline from submission to payout has slowed down significantly.”

    One other side effect of the vulnpocalypse is that as submissions increase, the price of many vulnerabilities is driven down. While this won’t kill the bug bounty ecosystem, it will reshape things — particularly for a certain class of researcher.

    The Vulnpocalypse Drives Bug Prices Down

    The impact is beginning to show up in bug economics. “I think the community is really nervous because one of the things that no one’s talking about yet is that the result is going to be driving the price of bugs down across the board,” Childs says.

    The ZDI executive explains that reported vulnerabilities previously were more limited, but “now everybody’s finding bugs.” As a result, the security research economy has become a buyer’s market. “The $2,000 to $50,000 bugs,” he adds, “I think those are going to become very scarce, or the price is going to be pressed down.”

    Bug researcher Wojciech Reguła says that “at least in the macOS space, bounty amounts have clearly gone down in some cases.”

    “For example, a full TCC/privacy bypass that used to pay around $30.5K may now be worth roughly $5K, while a more limited TCC bypass [Transparency, Consent, and Control] — for example, being able to dump all of a user’s photos without their consent — has gone from around $5K to $1K,” he says.

    Related:Exploited Zimbra Flaw Highlights Shrinking Window to Patch

    The AI Slop Effect

    The AI effect is more than just a volume issue. While more vulnerabilities are being discovered, AI has also enabled a glut of low-quality “slop” reports from those either looking to make a quick buck or perhaps newer researchers who don’t know where to put their effort.

    In January 2026, curl creator Daniel Stenberg announced it would end curl’s bug bounty program after seven years. He said the downfall started in late 2024 and “accelerated badly” in 2025. Historically, more than 15% of curl submissions resulted in confirmed vulnerabilities. By 2025, that number had fallen below 5%.

    “We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop — presumably because they too were actually misled by AI but with that fact just hidden better,” he wrote in a blog post. “The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk. Time and energy that is completely wasted while also hampering our will to live.”

    Apple responded to the glut of slop in its own way, by instituting reporting pauses for users who repeatedly submit ineligible reports.

    Related:N-able Bug Exposes Password Vault Master Keys

    HackerOne, Bugcrowd, ZDI, and others have decided to meet this challenge in similar ways — with AI-powered triaging to act as an initial filtering layer to assist human personnel. Or in other words, fighting AI with AI.

    While the aforementioned executives say they’re finding success with using AI to support the bug bounty process, this is still very much a problem that has not been fully solved. Triage times remain extended, as do payout times, and the executives broadly acknowledged that there’s still more work to be done.

    Not Quite Death of the Middle Class

    Undoubtedly, the shape of the bug bounty ecosystem is changing. The market for midtier bug payouts that many researchers count on appears to be compressing. But that doesn’t tell the full story, either.

    Sprague tells Dark Reading that bounty payments to HackerOne researchers are up 25% in the first half of this year over the same time period last year, and the number of researchers making $100,000 is also up 25%. She also says the number of new researchers has gone up “significantly.”

    Both things can be true at the same time: Total payouts can increase even as the value of many individual bug classes declines.

    Bugcrowd’s CEO Gerry believes that the price of individual bug findings will be compressed, particularly at the middle to low end. The flip side of this is that for researchers, bug hunting will become a “volume game,” where they will utilize modern tooling, particularly LLMs, to assist their existing skill set.

    Rather than earning $10,000 for one finding, researchers may increasingly rely on AI-assisted workflows to uncover larger numbers of lower-value findings. Gerry adds that 82% of researchers are now using AI to assist their workflows.

    Kunwar says he’s using AI in research “heavily,” but as a copilot rather than an autopilot. For source code review, for example, he built an internal tool that pairs static analysis with a local LLM. He also uses it for attack surface analysis and to automate tedious tasks associated with exploit development.

    That said, there are some things he won’t rely on AI for. “The judgment calls, the ‘is this real, is it exploitable, does it cross a boundary, how do I prove impact,’ those are mine,” Kunwar says.

    But AI has definitely compressed the time cycle for Kunwar. “I go from ‘this looks interesting’ to ‘I understand exactly what this is and how to demonstrate impact’ in hours instead of days,” he explains. “The rule I hold myself to is simple: If I can’t explain the bug and prove impact without the model, I didn’t find anything.”

    Another independent researcher, who identifies himself under the handle “Impost0r,” says he uses AI connected to his binary analysis tools to automate repetitive reverse-engineering work.

    An Enduring but Changed Bug Bounty Market

    The shape of the market may be changing, but there’s no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.

    That said, there could also be more opportunities for researchers. Sprague believes researchers can assist in other parts of the bug-hunting funnel going forward. Aaron Portnoy, chief product officer at Mindgard and a founder of the Pwn2Own hacking competition, says AI is accelerating development of new software, which means that it’s developing, in many cases, poorly written, flawed software.

    “No one I’ve spoken to feels like it’s going to take away the unique skill set that they have in a way that will basically put them out of a job,” Portnoy says.

    Whether AI ultimately creates more winners than losers remains an open question. Researchers will likely find themselves competing in a market where vulnerability discovery is cheaper and more abundant than ever before. But as Casey Ellis, the president and co-founder of Disclose.io who also previously started Bugcrowd, notes, “The ecosystem itself is not a static organism.”

    Today’s bug bounty middle class may not disappear, but it could look very different by the time the current storm passes.

    Bounty Bug Economy Repricing Vulnpocalypse
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

    You Need Cyber Deception for OT

    Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

    PaperCut releases second emergency patch for exploited flaws

    McKesson discloses breach after ShinyHunters claims patient data theft

    Offensive Security Investments Surge as AI Threats Increase

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ireland will be united, says Gordon Brown | Northern Ireland

    August 29, 2026

    Glencore threatened with $1.4bn lawsuit from embattled trader Radiant

    August 29, 2026

    Brave’s browser one-ups Chrome with its new support for email aliases

    August 29, 2026

    The Vulnpocalypse Is Repricing the Bug Bounty Economy

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ireland will be united, says Gordon Brown | Northern Ireland

    August 29, 2026

    Glencore threatened with $1.4bn lawsuit from embattled trader Radiant

    August 29, 2026

    Brave’s browser one-ups Chrome with its new support for email aliases

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.