Bug bounty programs eliminate or restrict payouts after low-quality AI reports crush triage
Low-quality AI reports overwhelmed triage capacity, driving Curl's confirmed vulnerability rate below 5% and exhausting TYPO3's bounty budget on duplicates, leading multiple major programs to suspend or gut cash rewards.
Who pays: Independent security researchers losing bounty income, maintainers spending triage time on automated noise, and software ecosystems exposed to vulnerabilities that go undiscovered by white-hat researchers