HackerOne Slashes Bug Bounty Rewards: What's the Impact on Security Research? (2026)

HackerOne's Bug Bounty Program: A Tale of Reduced Rewards and AI's Impact

The world of bug bounty hunting is undergoing a significant transformation, and HackerOne, a prominent platform in this domain, is at the center of this shift. The recent reduction in rewards for vulnerability reports has sparked intense debate among security researchers and project maintainers alike.

The Changing Landscape of Bug Bounty Rewards

HackerOne's Internet Bug Bounty (IBB) program, once a lucrative avenue for bug hunters, has seen a dramatic decrease in reward amounts. For instance, a medium-severity vulnerability that previously fetched $1,843 now earns a meager $297. Critical vulnerabilities, once rewarded with $9,250, now attract $2,257, while high-severity bugs have seen their payouts slashed from $4,429 to $1,009. Even low-severity bugs, once a lucrative find, now only yield $68.

This drastic reduction in rewards has left many researchers feeling disheartened and questioning the sustainability of their efforts. The trust between researchers and bug bounty programs is at an all-time low, as the rules of the game seem to change after the work is already done.

The AI Factor

One of the most intriguing aspects of this transformation is the role of AI-generated reports. Until recently, AI slop, or low-quality bug reports generated by AI, was dismissed as a minor issue. However, as AI models have become exponentially better at writing code and exploits, the situation has taken a turn.

Open source projects are now struggling to keep up with the influx of AI-generated reports, which still require human evaluation. This has led to a shift in the dynamics of the bug bounty landscape. Daniel Stenberg, the founder and lead developer of curl, famously stated that the project has stopped receiving AI slop reports, instead welcoming a surge of high-quality security reports, many of which are AI-assisted.

The Linux Kernel Conundrum

The Linux kernel community has been particularly affected by the rise of AI-assisted bug hunting. Linux kernel maintainer Greg Kroah-Hartman noted that AI-generated reports contain less slop and more valid concerns. However, the sheer volume of these reports has overwhelmed the project's security mailing list, making it almost unmanageable.

Linus Torvalds, the iconic Linux kernel boss, declared that the security mailing list has become almost entirely unmanageable due to the flood of duplicate reports from AI-assisted bug hunters. This situation highlights the double-edged sword of AI in bug bounty hunting.

The Human Element in Bug Bounty Hunting

At the heart of this debate is the human element in bug bounty hunting. Jakub Ciolek, a hacker who reported two denial-of-service bugs in Argo CD, found himself in a similar situation as Stenberg and Kroah-Hartman. He reported the bugs last fall, expecting a reward of around $8,500. However, HackerOne's delay in processing his report and the subsequent reduction in rewards left him feeling frustrated.

Ciolek argues that the economics of vulnerability reporting are changing rapidly. He believes that the discovery-first bug bounty model is becoming obsolete, as finding plausible bugs is becoming cheaper, and generating reports is easy to scale. The expensive part, he emphasizes, is still very human: verification, deduplication, impact assessment, coordination, and getting safe fixes shipped.

The Trust Issue and the Way Forward

The trust issue between researchers and bug bounty programs is a critical concern. Ciolek points out that the change in reward amounts was applied long after the work was completed, fixed, and publicly credited under different expectations. This unpredictability undermines the principles of responsible disclosure, which rely on researchers believing in a predictable process.

As a result, serious researchers are pricing in this risk, or even stopping their participation in bug bounty programs. Ciolek, for one, has ceased active bug bounty research, choosing to report serious issues as they arise, with a focus on verification and impact.

In conclusion, the reduction in bug bounty rewards and the rise of AI-assisted reports have sparked a reevaluation of the bug bounty model. The future of bug bounty hunting lies in rewarding more of the remediation cycle, not just the discovery phase. As the landscape continues to evolve, the human element in bug bounty hunting remains crucial, ensuring the sustainability and integrity of this vital practice in the open-source ecosystem.

HackerOne Slashes Bug Bounty Rewards: What's the Impact on Security Research? (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Catherine Tremblay

Last Updated:

Views: 6187

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.