Bug bounty programs eliminate or restrict payouts after low-quality AI reports crush triage
The case: Public vulnerability disclosure and bug bounty programs are suspending cash payouts, switching to unpaid disclosure, or moving to invite-only tiers after being overwhelmed by a flood of low-quality AI-generated reports and duplicates.
Who pays: Independent security researchers losing bounty income, maintainers spending triage time on automated noise, and software ecosystems exposed to vulnerabilities that go undiscovered by white-hat researchers