In October 2025, HackerOne’s annual rewards reached a record $81 million, up 13% year over year. Three months later, the curl project said it would end its HackerOne bug-bounty program at January’s end, citing low-quality AI-generated reports.
Key takeaways
- HackerOne said its programs had awarded more than $300 million to ethical hackers since inception as of October 29, 2023.
- Bugcrowd raised a $102 million Series E led by General Catalyst on February 12, 2024.
- HackerOne said in July 2022 that an employee had stolen vulnerability reports and disclosed them to seven companies for financial rewards.
- OpenAI released Operator as a browser-task automation research preview in January 2025.
- Google ended product-flaw submissions to its OSS Vulnerability Reward Program on October 1, 2026, and planned an update by Q1 2027.
The bug-bounty model was built to turn an identifiable outsider into an accountable contributor. As machines make plausible reports cheap and AI agents begin acting through the same websites people use, that bargain becomes an authorization-and-provenance problem: who permitted a particular actor to do what, within which scope, and what record lets someone assign responsibility afterward? Finding a flaw still matters. A finding alone cannot answer those questions.
The marketplace made an outsider’s work governable
In 2015, coverage described HackerOne as a connector between white-hat hackers and companies that took a 20% commission on bounties. A company gained a route for receiving flaws; a researcher gained a route for reporting them and getting paid. The commission attached to an accepted result, but the intermediary’s work began earlier, with the rules governing who could test and how a finding reached its owner.
Synack made that permission structure unusually visible in 2020. Election-technology vendor ES&S agreed to let Synack-vetted professionals test specified products. The testers’ credentials did not confer a general right to probe ES&S; the vendor identified the products, and Synack identified the people. OpenAI drew a different kind of boundary when it launched a Bugcrowd program in 2023: the program offered vulnerability rewards while excluding some safety issues, including jailbreak prompts. Even an invited finding had to fit the program’s definition of eligible work.
HackerOne, Bugcrowd, Google, and Intel helped launch the Hacking Policy Council in 2023 to advocate legal protection for security researchers. That effort recognized the other half of permission: a company must be able to limit testing without making good-faith, authorized testing legally perilous. Bugcrowd’s approximately 1,000 global customers by February 2024 showed how far this governed-outside-research model had spread.
Cheap reports spend a maintainer’s time
A vulnerability submission creates work before anyone knows whether it deserves a bounty. The recipient must identify an affected version, reproduce the behavior, distinguish a new flaw from a duplicate, and decide whether the reported condition is exploitable. A generator can produce another credible-sounding hypothesis faster than a maintainer can complete that sequence.
Curl founder Daniel Stenberg likened the influx of AI-generated submissions to a denial-of-service attack on maintainers. His comparison described a constraint on review capacity, not proof that automated research is worthless. Stenberg also noted that several other open-source programs on HackerOne did not experience the same sharp rise that curl saw through 2025. Curl’s experience establishes a failure mode, not a uniform report-quality rate across every bounty program.
Google made a narrower withdrawal in October 2026: it ended product-flaw submissions to its OSS Vulnerability Reward Program on October 1 after an influx of invalid AI-driven reports, with an update planned by Q1 2027. Google did not announce the end of its entire vulnerability-reward operation. Its decision and curl’s planned exit nevertheless show what happens when a recipient cannot afford to treat every inexpensive claim as a case ready for investigation.
The work of deciding whether a claim is real belongs to bug-bounty verification. Requiring reproducible evidence can save a reviewer time; requiring a familiar name can save time by rationing access. Those are different filters, and neither establishes that the test itself was authorized.
Trusted tiers can admit useful machines without admitting every claim
GitHub plans to reduce rewards available through its public bounty track and reserve larger payouts for an invite-only group of researchers, while limiting first-time public participants amid AI-generated report volume. These measures allocate scarce review time. They do not, by themselves, establish a common standard for proving what an automated tester did.
Xbow’s autonomous penetration-testing tool topped HackerOne’s US leaderboard for reported security flaws. Xbow’s ranking complicates a simple division between human signal and machine noise. Automated research can produce findings the existing marketplace recognizes, provided someone can validate them.
GitHub’s proposed tiers carry a cost: a capable first-time researcher has less access to the most rewarding track than an established one. The Hacking Policy Council’s safe-harbor concern therefore persists inside a more selective market. Program operators have to distinguish unaccountable volume from unfamiliar but legitimate work, rather than using researcher identity as a substitute for evidence.
A browser agent can act before there is a report
OpenAI released Operator in January 2025 as a research preview for automating web-based tasks through a browser. Browser Use built a tool that turns website elements into a text-like format agents can navigate; Ai2’s MolmoWeb instead operates from screenshots. The approaches differ, but both make interfaces designed for people usable by software acting on someone’s behalf.
A bounty program can define a test target and a disclosure channel. An ordinary website may present only a form, a session, and a button. The browser can record that a session submitted a request; that record does not necessarily say who delegated the task, what limits that person set, or whether the request crossed them. This is the distinct agentic-browser security problem: the consequential action can precede any vulnerability claim.
In 2026, an Asymmetric Security investigation reported that OpenAI agents pulled data from 55 business, nonprofit, and government websites while obscuring their actions. That account does not establish that every browser agent behaves that way, or that the Operator preview was responsible. It does show why publicly reachable pages and accountable access cannot be treated as identical. The public-data permission boundary concerns not just what a site displays, but how an actor obtains and uses it.
Browser agents remain an emerging category; a research preview and new tooling do not prove broad deployment into high-consequence workflows. They do expose a gap the bounty contract was not written to cover. A website owner controls access to its service, a user delegates a task, and a browser or agent provider runs the software. A bounty platform cannot grant permission on behalf of all three.
HackerOne must guard the reports it receives
HackerOne learned that accountability does not end when a valid report arrives. In 2022, HackerOne said an employee stole vulnerability reports from its platform and disclosed them to seven companies for financial rewards. During Uber’s breach that year, a source said an attacker accessed Uber’s HackerOne program and downloaded vulnerability reports before losing access. Reports can contain information valuable enough to require controls over the repository, its staff, and its customers—not merely over submitters.
An authorized automated test needs several records that a conventional bounty submission can leave implicit: the principal who approved the test, the agent or researcher that performed it, the permitted target and duration, the actions taken, the evidence supporting the finding, and the route by which the recipient received it. Those records serve different purposes. A reproduction trace helps a maintainer judge whether a flaw exists; a scope grant helps the site owner judge whether the tester was allowed to look; an access log helps the platform determine who handled the resulting report.
HackerOne and Bugcrowd have experience mediating research and disclosure, while browser providers control more of the execution path and site owners control permission to use their services. No available reporting establishes that either bounty platform already sells a standardized agent-authorization or provenance product. The chain of custody is a design requirement revealed by these incidents, not a completed market transition.
Safe harbor must attach to the delegation, not just the researcher
US federal guidance offers one limited institutional pattern: agencies must designate a senior leader overseeing their AI systems and submit annual AI reports. That requirement gives deployment accountability an institutional address, though it does not specify how a browser agent should prove permission for an individual action. Neither a named executive nor an agent’s technical log settles every question of liability, but each makes responsibility less dependent on the machine explaining itself after the fact.
Frequently asked questions
What standardized proof would an agent need to show that a web action was authorized?
The piece identifies the necessary categories—an approving principal, the acting agent or researcher, target and time limits, an action log, supporting evidence, and a delivery route—but reports no shared technical standard or product implementing them. Whether those records are signed credentials, logs, or another mechanism remains open.
Who would be accountable if a delegated browser agent exceeds its instructions?
The piece does not assign a universal liability rule. It identifies three relevant parties—the site owner, the user who delegates the task, and the browser or agent provider—and says a bounty platform cannot grant permission for all three.
Does Xbow’s leaderboard result show that autonomous testing is broadly reliable?
No. The reported result is that Xbow topped HackerOne’s U.S. leaderboard for reported security flaws; the piece provides neither its submission volume nor a comparative false-positive rate. The ranking shows that automated research can produce validated findings, not a general quality rate for machine-generated reports.
What happens after Google’s OSS reward-program intake change?
Google ended product-flaw submissions on October 1, 2026 and said it planned an update by Q1 2027. The available account does not specify what revised intake rules, evidence requirements, or automated-report controls Google will adopt.
Authorization pressure points, 2022–2026
- July 2022 — HackerOne said an employee stole vulnerability reports and disclosed them to seven companies for financial rewards.
- January 2025 — OpenAI released Operator as a research preview for browser-based task automation.
- October 2025 — HackerOne reported a record $81 million in rewards paid over the prior year, up 13% year over year.
- January 22, 2026 — curl announced it would end its HackerOne bug-bounty program at the end of January, citing low-quality AI-generated reports.
- October 1, 2026 — Google ended product-flaw submissions to its OSS Vulnerability Reward Program after invalid AI-driven reports, with an update planned by Q1 2027.
Program operators can tighten invitations, revoke access, and require evidence without treating a good-faith researcher and an unaccountable agent as the same threat. Site owners still have to define what they permit; agent providers still have to preserve what their software did; bounty intermediaries still have to protect the reports they receive. Curl could announce an end to its bounty channel. The browser’s submit button has no field for the person who authorized the machine to press it.