The bug bounty model is under strain as AI dramatically lowers the cost of finding and submitting vulnerability reports, while validation and remediation costs remain unchanged. High-profile programs like the Internet Bug Bounty, Node.js, and curl have paused or removed payouts after being overwhelmed by AI-generated

9m read timeFrom aikido.dev
Post cover image
Table of contents
Why bug bounty worked so wellWhat’s breaking nowThis is an old problem, amplifiedOpen source is the first to feel the impactWhat happens when you remove financial incentivesBreaking the system to improve itHackers aren’t going anywhereWhat happens next

Sort: