AI-generated "junk reports" are flooding in, and responses can't keep up: an unusual turn in bug bounty programs, as seen in security circles lately

TL;DR AI
2 min readKey summary
AI-generated low-quality vulnerability reports are flooding bug bounty programs, creating triage fatigue and slowing responses to real risks.
HackerOne has paused new OSS submissions after a surge of invalid reports, while Node.js suspended its bounty program.
curl has ended its program, and Google tightened submission requirements to reduce noisy, low-value reports.
The trend raises concern that automated hallucinated reports could overwhelm security teams and undermine bounty incentives.



