Merton101 · Case 25 · Open source and security
Bug bounty programs eliminate or restrict payouts after low-quality AI reports crush triage
Reported 23 Sep 2026 · entered the ledger 25 Sep 2026 · last checked 25 Sep 2026 · Side effect
Public vulnerability disclosure and bug bounty programs are suspending cash payouts, switching to unpaid disclosure, or moving to invite-only tiers after being overwhelmed by a flood of low-quality AI-generated reports and duplicates.
The institution
Bug bounty programs (Curl, HackerOne, GitHub, TYPO3, Intel)
institution
The mechanism
Friction removed
externality scale 3 of 5, fast
Adaptation
reform
the rule itself was rewritten
The case
- The assumption that broke
- Vulnerability reporting requires genuine human effort and technical comprehension, which naturally kept submission volume manageable for triage teams.
- The first-order effect
- Low-quality AI reports overwhelmed triage capacity, driving Curl's confirmed vulnerability rate below 5% and exhausting TYPO3's bounty budget on duplicates, leading multiple major programs to suspend or gut cash rewards.
- Who pays
- Independent security researchers losing bounty income, maintainers spending triage time on automated noise, and software ecosystems exposed to vulnerabilities that go undiscovered by white-hat researchers · group: Platform workers
- Scale and speed
- 3 of 5 · fast
Evidence
-
X ↗
23 Sep 2026
· social source, review
Curl ended payouts after AI slop drove confirmed-vuln rates under 5%. HackerOne paused new Internet Bug Bounty submissions. GitHub slashed public payouts and reserved real money for an invite-only tier. TYPO3 killed its public bounty after the 2026 budget ran out under AI-generated duplicates. Intel just suspended a program that used to pay up to $100,000 and replaced it with unpaid disclosure. The stated reason is almost always the same: volume of low-quality AI reports crushed triage.
The second reader
| Claim | Verdict | Note |
|---|---|---|
| ShinyHunters used it as a zero-day from late May into early June 2026 against on the order of 100 organizations, mostly education, and stole data at scale. | supported | Page states verbatim: "ShinyHunters used it as a zero-day from late May into early June 2026 against on the order of 100 organizations, mostly education, and stole data at scale." |
| Curl ended payouts after AI slop drove confirmed-vuln rates under 5%. | supported | Page states verbatim: "Curl ended payouts after AI slop drove confirmed-vuln rates under 5%." |
| HackerOne paused new Internet Bug Bounty submissions. | supported | Page states verbatim: "HackerOne paused new Internet Bug Bounty submissions." |
| GitHub slashed public payouts and reserved real money for an invite-only tier. | supported | Page states verbatim: "GitHub slashed public payouts and reserved real money for an invite-only tier." |
| TYPO3 killed its public bounty after the 2026 budget ran out under AI-generated duplicates. | supported | Page states verbatim: "TYPO3 killed its public bounty after the 2026 budget ran out under AI-generated duplicates." |
| Intel just suspended a program that used to pay up to $100,000 and replaced it with unpaid disclosure. | supported | Page states verbatim: "Intel just suspended a program that used to pay up to $100,000 and replaced it with unpaid disclosure." |
| The stated reason is almost always the same: volume of low-quality AI reports crushed triage. | supported | Page states verbatim: "The stated reason is almost always the same: volume of low-quality AI reports crushed triage." |