
Table of contents
20
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: AI helps you find and write faster, but it doesn’t help you win bug bounties on its own, because winning means a valid, non-duplicate, in-scope report from a program that still pays.
- The hit rates are all over the place. In XBOW’s mid-2025 write-up, about 12% of roughly 1,060 submissions were resolved and about 20% were duplicates. Curl’s confirmed-report rate fell from over 15% to under 5%.
- AI is better at the known bug than the new one. On a 2025 benchmark of real bounties, the top agent detected 12.5% of unseen vulnerabilities but patched 90% of known ones.
- Cheap discovery is changing the payouts. HackerOne paused the Internet Bug Bounty, GitHub cut public payouts by at least half, and Apple capped submissions.
- Programs now gate by reputation. GitHub gives new researchers four initial submissions, and HackerOne routes by researcher signal.
- What helps you win bug bounties is verified depth. Run the five-check slop test below before submitting anything an AI found.
AI makes finding candidate bugs cheap, and when something gets cheap, the thing you were paid for stops being scarce.
If you’ve pointed an AI tool at a target and wondered whether it gives you an edge, the answer depends on what it means to win bug bounties. A report that gets closed as a duplicate or “informative” didn’t win bug bounties, however fast you found it.
Here’s what the public data says about whether AI helps you win bug bounties, where it doesn’t, and what to do about it.

To win bug bounties, a finding has to clear five gates, and AI affects them very differently:
Most of the excitement about AI lives at gate one. Most of what stops people who want to win bug bounties happens at gates three to five.
No single study answers whether AI helps you win bug bounties, so here are the five best data points we found, each with its limits.
| Source | What it measured | Result | Caveat |
|---|---|---|---|
| XBOW, mid-2025 | An autonomous system’s HackerOne submissions | ~1,060 submitted: 130 resolved, 208 duplicate, 209 informative | Humans reviewed before submission; many statuses still pending |
| HackerOne, Oct 2025 | Autonomous “hackbot” submissions | 560+ valid; 1,100+ submitted, nearly half valid; 78% of valid ones were XSS | Valid findings clustered in one bug class |
| curl, Jan 2026 | Valid-report rate on one program | Over 15% historically, under 5% from 2025 | One open-source project, human-and-AI mix |
| BountyBench, 2025 | AI agents on 40 real bounties | Detect 12.5%, exploit 67.5%, patch 90% (best agents) | 2025-era models; capability has moved since |
| curl and Joshua Rogers, 2025 | AI scanners plus a human filter | About 50 fixes merged | Mostly small mistakes, not necessarily bounty-grade |
XBOW’s own breakdown of its climb up HackerOne’s leaderboard is the most direct win-rate data for an AI system. Of roughly 1,060 submissions, 130 were resolved (about 12%), 303 triaged (29%), 208 duplicates (20%), 209 informative (20%), and 36 not applicable (3%), with the rest pending.
Two caveats matter. XBOW’s security team reviewed findings before submission, and the listed statuses add up to 1,044 rather than 1,060, so treat the percentages as approximate. XBOW also attributes many informative closures to program rules, such as excluded vulnerability classes.
Even for the best-resourced AI system on the platform, about one in five submissions was a duplicate and one in five was informative. Speed didn’t help it win bug bounties outright, because the other categories didn’t go away.
HackerOne’s 2025 report says autonomous agents submitted 560+ valid reports. Its researcher-signals post adds that there were over 1,100 hackbot submissions, nearly half valid, and that 78% of the valid ones were XSS.
That’s a much better hit rate than curl’s, but it’s concentrated in a pattern-matching bug class, which is also the class where duplicates stack up. The same post says reports written entirely by AI tend to be polished but technically shallow, and easy for triage to spot.
Daniel Stenberg’s post on ending curl’s bounty says the program produced 87 confirmed vulnerabilities and over $100,000 in rewards. It also says confirmed reports used to be “north of 15%” of submissions and fell below 5% starting in 2025. The bounty ended January 31, 2026.
The same project shows the other side. The Register reported that about 50 fixes came from Joshua Rogers’ reports, made with AI scanning tools plus his own filtering. Stenberg called most of them small mistakes and nits, but still worth fixing. That’s AI used well, and it still wasn’t a bounty-sized windfall.
BountyBench tested agents on 40 real bounties, from $10 to $30,485, in three modes. The best agent detected 12.5% of unseen vulnerabilities, the best exploited 67.5% of known ones, and the best patched 90%.
Bounties pay for the new bug, which is the hardest of the three and the one that decides who can win bug bounties. One big caveat: these were 2025-era models. HackerOne says its report volume more than doubled after advanced models arrived in February 2026, so read 12.5% as a floor, not a ceiling.

When discovery gets cheap, programs respond by making payouts harder to get. That’s the pattern in 2026, and it changes how you win bug bounties.
GitHub’s change is the clearest example:
| GitHub public program | Before (per The Hacker News) | After July 27, 2026 |
|---|---|---|
| Low | $617 to $2,000 | $250 |
| Medium | $4,000 to $10,000 | $2,000 |
| High | $10,000 to $20,000 | $5,000 |
| Critical | $20,000 to $30,000+ | $10,000 |
Qualified researchers get a separate invite-only VIP tier, with $30,000 or more for criticals. New researchers get “up to four initial submissions” until they meet a HackerOne Signal threshold. Per The Hacker News, GitHub put it this way: you earn more by submitting better, not by submitting more.

It’s not all contraction. HackerOne paid $81M in its latest reporting year, up 13%, and Google paid a record $17M in 2025. Total money is up. What’s changing is who gets it: established, high-signal researchers over anonymous volume. Treat this as our reading of the pattern, since no source states it as a single trend.
None of this means AI is useless. Here’s where it earns its place when you’re trying to win bug bounties:
Bugcrowd also found more experienced hackers are slightly more likely to use AI, since they know what’s tedious and what’s creative. AI rewards people who already know what they’re doing.
If you want to win bug bounties with AI, make this the one checklist you remember. Run it on every AI-found finding before it leaves your machine:
The census puts the line well: autonomy, not authorship, is where programs draw it. That’s the same distinction between curl’s flood and Rogers’ fixes.
If AI is table stakes, the way to win bug bounties moves elsewhere:
If you’re starting out, our roadmap to becoming a bug bounty hunter sequences all of this.
We sell an AI agent for bug bounty work, so you should weigh our view accordingly, and we’d rather tell you what it does and doesn’t do. Our agent guide describes findings being logged as raw evidence first, with a human checking before anything is called real, and says hunt sessions and scope details stay on your own machine.
That design follows the slop test: the agent speeds up the find step and the evidence gathering, and you do the verification. On a live YesWeHack CTF called “Deadbolt,” our agent solved it fully autonomously in about three minutes. That’s a good example of lowering the cost of an attempt, and it’s not a prediction that you’ll get paid more.
The honest limit: a tool like ours raises your floor, but it won’t help you win bug bounties by itself, because it can’t give you signal, scope knowledge or judgment. Individual plans start at $20 a month, with a 7-day free trial and no credit card. We’d suggest using the free week to see whether it helps you produce a finding you can verify yourself, before you pay for anything.
It helps you find and draft faster, but winning needs a valid, non-duplicate, in-scope report from a program that still pays. In XBOW’s mid-2025 data, about 12% of submissions were resolved and about 20% were duplicates, so speed alone didn’t convert to wins.
Use it for recon, candidate generation and drafting, then verify everything yourself. To win bug bounties with AI, reproduce each finding from scratch, confirm scope and the program’s AI rules, check for duplicates, and write the report in your own words.
A July 2026 census of 53 programs found none ban AI outright. But HackerOne’s Code of Conduct holds researchers responsible for submission quality, and fabricated or unverified reports can be penalized. Eight of the 16 programs with AI clauses refuse fully autonomous submissions.
There’s no single number. HackerOne reported nearly half of over 1,100 hackbot submissions were valid, curl’s confirmed rate fell below 5%, and about 12% of XBOW’s submissions were resolved. It depends on the system, the human filtering and the program.
Total payouts are up: HackerOne paid $81M in its latest year, and Google paid a record $17M in 2025. But individual programs are cutting. GitHub’s public payouts dropped by at least half on July 27, 2026, and the Internet Bug Bounty paused new submissions.
Mostly yes, with conditions. Of 16 programs with AI clauses in the July 2026 census, 13 require you to verify findings yourself, 11 require a working reproduction, and only 3 require you to disclose AI use. Always read the specific program’s policy.
Known ones. On BountyBench’s 2025 tasks, the best agent detected 12.5% of unseen vulnerabilities but exploited 67.5% of known ones and patched 90%. Newer models have likely moved those numbers, so treat them as a floor.
AI helps you win bug bounties at one gate out of five, the find, and the market is responding by raising the bar on the other four. The people who come out ahead will be those who use AI for speed and then do the part it can’t, which is proving the bug is real, in scope, new and worth paying for.
Run the slop test, build a record of valid reports, and aim at the logic and chained flaws that tools still miss. Volume was never how people win bug bounties, and in 2026 the programs are saying so out loud.
Categories
Related articles