Bug Bounty Spam: AI-Generated Slop Is Polluting Cybersecurity Programs
From hallucinated vulnerabilities to fake technical writeups, LLM-generated bug reports are overwhelming security teams and threatening the trust behind responsible disclosure
The New Threat: AI Slop in Cybersecurity
Bug bounty programs were built on trust—ethical hackers flagging real flaws in exchange for rewards. But with the rise of large language models (LLMs), a new and insidious challenge has emerged: AI slop.
This refers to low-quality, often fake reports generated by AI tools that claim to uncover vulnerabilities that don’t actually exist. These submissions mimic the form of real bug reports—with technical jargon and plausible structure—but lack any substance.
- “People are receiving reports that sound reasonable,” says Vlad Ionescu, CTO of RunSybil.
- “But the technical details are just made up… it was a hallucination all along.”
False Positives, Fake Reports, and Frustrated Developers
The effects of this growing trend are being felt across bug bounty platforms and open-source projects alike:
- The Curl project received a bogus report that was easily debunked as AI slop.
- Open Collective reported inboxes flooded with low-effort AI submissions.
- The CycloneDX project temporarily shut down its bounty program due to a deluge of fake reports.
Even mainstream platforms like HackerOne and Bugcrowd are seeing the impact:
- Michiel Prins of HackerOne confirms a rise in LLM-generated false positives, calling them “low-signal submissions” that erode program efficiency.
- Casey Ellis of Bugcrowd notes a weekly increase of 500 submissions, though he says most AI use has yet to result in a major spike in low-quality slop.
Why AI-Generated Reports Are So Deceptive
AI-generated bug reports look legitimate. That’s part of the problem.
- LLMs are designed to be helpful—they generate answers even when no bug exists.
- The reports often include credible-sounding vulnerabilities, code snippets, and detailed explanations, fooling even experienced analysts at first glance.
- These false reports waste time, dilute trust, and clog security workflows.
“We’re getting a lot of stuff that looks like gold, but it’s actually just crap,” Ionescu summed up bluntly.
AI vs. AI: A Triage Arms Race
To fight back, companies are turning to AI-powered filtering systems.
- HackerOne recently launched “Hai Triage”, a system that uses AI to flag duplicates, identify noise, and prioritize credible threats.
- Human analysts still review reports, but now with AI agents assisting behind the scenes.
- RunSybil, Ionescu’s startup, is also working on AI agents to vet submissions at scale.
The goal: automate early detection of slop, while ensuring real vulnerabilities don’t get lost in the noise.
Not Everyone’s Affected—Yet
Interestingly, not all organizations are experiencing the same surge in fake reports.
- Mozilla, which manages Firefox’s bug bounty, reports a steady rejection rate under 10%, with no noticeable increase in AI-generated slop.
- Their reviewers don’t use AI filters, fearing it might mistakenly reject legitimate bugs.
Meanwhile, major players like Google, Meta, and Microsoft declined to comment, despite their heavy investments in both AI and security.
What’s Next: Triage, Trust, and the AI Paradox
The rise of AI slop highlights a deepening paradox in cybersecurity:
- AI is both the problem and the solution—used to generate slop, but also essential for filtering it.
- Humans remain central, especially when stakes are high and nuance matters.
- As more hackers and companies adopt LLMs, the fight will shift toward AI-assisted verification, contextual intelligence, and real-time prioritization.
Ultimately, the future of bug bounty programs may hinge on who builds the smarter AI—attackers or defenders.








