Bug bounty isn’t dead, but the old model is breaking
ID: ebc8d077-ab5b-5469-8a71-855f07b6ddf4
STIX ID: report--ebc8d077-ab5b-5469-8a71-855f07b6ddf4
Feed Name: Aikido Security's Blog
This article analyzes how AI-driven increases in low-quality and high-volume bug bounty submissions are overwhelming maintainers and prompting major programs (e.g., Internet Bug Bounty, curl, Node.js) to pause or change payouts, arguing the bug bounty model must evolve toward disclosure-as-expected, more targeted rewards, and improved triage to remain sustainable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
