AI Models Are Flooding Bug Bounty Programs, Reshaping Cybersecurity Economics
Summary
- • AI agents are tripling researcher bug submissions, overwhelming corporate bounty programs
- • Google projects 2–10x higher bug payouts as agentic discovery floods the market
- • Criminal actors confirmed using AI to develop zero-day exploits, bypassing 2FA systems
- • The 90-day responsible disclosure window is obsolete in an AI-accelerated threat environment
Details
Researcher submissions up ~3x year-over-year
Independent researcher Joseph Thacker reports submitting three times more bugs than a year prior, attributing the surge to AI-assisted discovery tools he developed and deployed in his own work.
Google projected to pay 2–10x more in bug bounties
Thacker estimates major tech companies like Google could spend two to ten times their prior annual bug bounty payouts; smaller organizations lack the financial reserves to absorb this pressure and may not survive the economics.
Criminal actors confirmed using AI for zero-day exploitation
Google Threat Intelligence Group observed 'prominent cyber crime threat actors' using AI-generated tools to discover and exploit a zero-day vulnerability targeting 2FA bypass on an open source system administration platform. Google notified the developer and a fix was issued.
90-day disclosure window under existential pressure
Security researcher Himanshu Anand: 'The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines.'
Near-term bug surfeit followed by medium-term market correction
Thacker forecasts submission volumes may eventually fall as AI tools exhaust accessible vulnerabilities — shifting researcher economics toward high-severity, novel findings that require deeper expertise, with payouts rising again for the hardest bugs.
Key data points from Wired investigation into AI's impact on vulnerability research and bug bounty economics
What This Means
AI-powered vulnerability discovery is simultaneously flooding bug bounty programs with valid submissions and arming attackers with AI-generated zero-day exploits, with criminal use now confirmed in the wild by Google's Threat Intelligence Group. Security teams should anticipate 2–10x payout pressure in the near term while reviewing patch deployment pipelines, as the 90-day disclosure window was built for a pre-AI world that no longer exists. Independent researchers can expect near-term volume opportunities as AI surfaces accessible bugs, followed by a market correction that concentrates rewards around the most novel and high-severity findings.
