While having a bug bounty program is considered best practice as part of a broader offensive security program, the results are often unpredictable. As more practitioners start to disregard these low-quality bug submissions—now being termed “AI slop”—the impact is diminishing. While the idea of thousands of testers finding issues is appealing, the value of bug bounty programs isn’t meeting expectations.
Some challenges with bug findings:
- The vast majority of crowd-submitted bugs to bug bounty companies are not actual vulnerabilities.
- Few submitted bugs have enough information attached to make a determination about the severity of the bug.
- Only a small handful of professional bug hunters are diligent in providing useful writeups of their bugs.
- Proving a bug is a security vulnerability requires proof of exploit, which isn’t always easy to do.
- The unpredictability of findings means you can’t predict what to budget for bug bounties.