September 30, 2026
Two Bug Bounty Programs Just Died. One Just Opened. Hereβs What That Tells Me.
The AI slop crisis is killing some programs and making others double down. Beginners need to know the difference.

By Riya Limba
3 min read
The AI slop crisis is killing some programs and making others double down. Beginners need to know the difference.
I read the Decred announcement on a Saturday and felt something I hadn't expected: recognition.
"Report verbosity is increasing and quality is decreasing. Processing these reports is becoming a severe drain on resources that is not sustainable in the long term."
They called it "sloptimism" β a term borrowed from Bugcrowd's Trey Ford, describing "overly optimistic submissions driving large volumes of speculative or AI-generated reports submitted with minimal to no pre-submission validation" .
Decred put its entire program on hiatus. Not because the bugs stopped coming. Because the noise made it impossible to find them.
Two days later, I read that Intel had done the same thing. The Intigriti page now says "suspended." The new program is "a responsible disclosure program without bounties" .
Intel's program paid up to $100,000. Now it pays nothing.
I closed both tabs and sat there for a minute.
Then I opened Vercel's blog and read something that made me feel something different.
The Vercel Decision
On September 23, Vercel announced that its bug bounty program was going fully public .
Not shrinking. Not going invite-only. Opening.
Their reasoning:
"AI has fundamentally changed the nature of bug bounty programs, exponentially increasing the number of reports, both valid and invalid. Some companies are responding by moving to private programs. At Vercel, we've found that public reports are still surfacing real, valuable findings."
They built tooling to filter noise. They streamlined triage. They consolidated their programs. And then they opened the door wider.
"We believe in evaluating reports on their own merit" .
I read that sentence three times.
Why This Matters for Beginners
Here's the uncomfortable reality of the moment.
The easy path is closing. Decred is gone. Intel is gone. GitHub cut public payouts by 50β59% and added submission caps for new researchers . Curl ended its bounty program entirely . Microsoft's average payout dropped from $49,000 to $35,000 even as total spending hit a record $20 million .
The volume of AI-generated reports has made the traditional "submit everything you find" model unsustainable. Companies are responding by either shutting down, going invite-only, or slashing payouts.
But not everyone is responding the same way.
Vercel looked at the same flood of AI reports and decided the answer wasn't to close the door. It was to build better filters and keep the door open .
OpenJS just launched a Security Stewardship Program with $100,000 minimum annual contributions from partners, explicitly designed to fund both bug bounties and maintainer patching work for Node.js . Socket and Aikido are anchoring it.
Arbitrum's new security program includes "preliminary AI-assisted screening" alongside traditional audits and bug bounties .
The programs that are surviving aren't doing it by hiding. They're doing it by adapting.
What I'm Actually Learning From This
I don't have access to Vercel's internal triage data. I can't see what percentage of their public reports turn out to be valid. But I can read their words and notice what they're saying: AI-assisted research is producing real findings, not just slop.
The problem isn't that AI makes bug hunting too easy. The problem is that AI makes it easy to submit without understanding. The reports that flood programs aren't from researchers who found something and documented it carefully. They're from people who ran a tool, got output, and pasted it into a report form.
The difference between slop and signal isn't whether AI was involved. It's whether a human understood what they were looking at.
What I'm Doing Differently
I'm not going to pretend I can predict which programs will survive. I can't. But I can change how I choose where to spend my time.
I'm looking for programs that still pay for public findings. Vercel is on the list. The OpenJS-backed Node.js program is on the list. There are others. The programs that are closing aren't the only options.
I'm treating every report like it's the only one I'll ever write. Not because I'm dramatic. Because the bar has risen. A report that looks like it was generated in five minutes will be treated like it was generated in five minutes.
I'm paying attention to which programs are adapting, not just which ones are big. A smaller program that's investing in triage tooling and keeping public submissions open is worth more of my time than a famous program that's going invite-only.
The Honest Truth
I'm a beginner. I've found one confirmed bug. The programs I'm learning on might not exist in a year.
But the Vercel decision gave me something I didn't expect: a reason to believe the path isn't closing for people like me.
The companies that are adapting β building filters, funding maintainers, keeping public doors open β they're betting that the signal is still there. That real researchers with real findings can still stand out from the noise.
I don't know if they're right. But I know which side of the bet I want to be on.
If you're also navigating the split between programs that are closing and programs that are opening, I write about what I'm actually figuring out β confusion included. Follow for more field notes from the bottom of the learning curve.