As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.
It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.
Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”
Ashish Kunwar, vulnerability researcher at GanaSec and a long-time bug bounty researcher, tells Dark Reading that, “Since last year, the entire pipeline from submission to payout has slowed down significantly.”
One other side effect of the vulnpocalypse is that as submissions increase, the price of many vulnerabilities is driven down. While this won’t kill the bug bounty ecosystem, it will reshape things — particularly for a certain class of researcher.
The Vulnpocalypse Drives Bug Prices Down
The impact is beginning to show up in bug economics. “I think the community is really nervous because one of the things that no one’s talking about yet is that the result is going to be driving the price of bugs down across the board,” Childs says.
The ZDI executive explains that reported vulnerabilities previously were more limited, but “now everybody’s finding bugs.” As a result, the security research economy has become a buyer’s market. “The $2,000 to $50,000 bugs,” he adds, “I think those are going to become very scarce, or the price is going to be pressed down.”
Bug researcher Wojciech Reguła says that “at least in the macOS space, bounty amounts have clearly gone down in some cases.”
“For example, a full TCC/privacy bypass that used to pay around $30.5K may now be worth roughly $5K, while a more limited TCC bypass [Transparency, Consent, and Control] — for example, being able to dump all of a user’s photos without their consent — has gone from around $5K to $1K,” he says.
The AI Slop Effect
The AI effect is more than just a volume issue. While more vulnerabilities are being discovered, AI has also enabled a glut of low-quality “slop” reports from those either looking to make a quick buck or perhaps newer researchers who don’t know where to put their effort.
In January 2026, curl creator Daniel Stenberg announced it would end curl’s bug bounty program after seven years. He said the downfall started in late 2024 and “accelerated badly” in 2025. Historically, more than 15% of curl submissions resulted in confirmed vulnerabilities. By 2025, that number had fallen below 5%.
“We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop — presumably because they too were actually misled by AI but with that fact just hidden better,” he wrote in a blog post. “The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk. Time and energy that is completely wasted while also hampering our will to live.”
Apple responded to the glut of slop in its own way, by instituting reporting pauses for users who repeatedly submit ineligible reports.
HackerOne, Bugcrowd, ZDI, and others have decided to meet this challenge in similar ways — with AI-powered triaging to act as an initial filtering layer to assist human personnel. Or in other words, fighting AI with AI.
While the aforementioned executives say they’re finding success with using AI to support the bug bounty process, this is still very much a problem that has not been fully solved. Triage times remain extended, as do payout times, and the executives broadly acknowledged that there’s still more work to be done.
Not Quite Death of the Middle Class
Undoubtedly, the shape of the bug bounty ecosystem is changing. The market for midtier bug payouts that many researchers count on appears to be compressing. But that doesn’t tell the full story, either.
Sprague tells Dark Reading that bounty payments to HackerOne researchers are up 25% in the first half of this year over the same time period last year, and the number of researchers making $100,000 is also up 25%. She also says the number of new researchers has gone up “significantly.”
Both things can be true at the same time: Total payouts can increase even as the value of many individual bug classes declines.
Bugcrowd’s CEO Gerry believes that the price of individual bug findings will be compressed, particularly at the middle to low end. The flip side of this is that for researchers, bug hunting will become a “volume game,” where they will utilize modern tooling, particularly LLMs, to assist their existing skill set.
Rather than earning $10,000 for one finding, researchers may increasingly rely on AI-assisted workflows to uncover larger numbers of lower-value findings. Gerry adds that 82% of researchers are now using AI to assist their workflows.
Kunwar says he’s using AI in research “heavily,” but as a copilot rather than an autopilot. For source code review, for example, he built an internal tool that pairs static analysis with a local LLM. He also uses it for attack surface analysis and to automate tedious tasks associated with exploit development.
That said, there are some things he won’t rely on AI for. “The judgment calls, the ‘is this real, is it exploitable, does it cross a boundary, how do I prove impact,’ those are mine,” Kunwar says.
But AI has definitely compressed the time cycle for Kunwar. “I go from ‘this looks interesting’ to ‘I understand exactly what this is and how to demonstrate impact’ in hours instead of days,” he explains. “The rule I hold myself to is simple: If I can’t explain the bug and prove impact without the model, I didn’t find anything.”
Another independent researcher, who identifies himself under the handle “Impost0r,” says he uses AI connected to his binary analysis tools to automate repetitive reverse-engineering work.
An Enduring but Changed Bug Bounty Market
The shape of the market may be changing, but there’s no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.
That said, there could also be more opportunities for researchers. Sprague believes researchers can assist in other parts of the bug-hunting funnel going forward. Aaron Portnoy, chief product officer at Mindgard and a founder of the Pwn2Own hacking competition, says AI is accelerating development of new software, which means that it’s developing, in many cases, poorly written, flawed software.
“No one I’ve spoken to feels like it’s going to take away the unique skill set that they have in a way that will basically put them out of a job,” Portnoy says.
Whether AI ultimately creates more winners than losers remains an open question. Researchers will likely find themselves competing in a market where vulnerability discovery is cheaper and more abundant than ever before. But as Casey Ellis, the president and co-founder of Disclose.io who also previously started Bugcrowd, notes, “The ecosystem itself is not a static organism.”
Today’s bug bounty middle class may not disappear, but it could look very different by the time the current storm passes.


