Could AI tools put bug bounty hunters out of work?
Meanwhile, AI-native kids are pursuing bug bounties.
• 3 min read
A lack of bugs might not be the first thing most people complain about, but for bug bounty hunters, empty nets are a bad sign for business.
For years, bug bounty hunters have earned cash—with some rewards from companies like Google hitting the six-figure mark—by finding and alerting companies to vulnerabilities in their websites and other IT infrastructure. However, Cris Thomas, security advocate at cybersecurity company Semgrep, told IT Brew that he expects to see AI change the bug bounty program in the next six months to a year.
AI is getting better about finding security flaws in software, especially the newer frontier models; meanwhile, in-house cybersecurity teams at companies like Google are using AI to triage vulnerabilities faster.
“The price for the bugs that [hunters find] is going to increase, because there are going to be fewer bugs that are going to be available for bug bounty, fewer people to be able to find them, and so supply and demand, price is going to go up,” Thomas said, adding that bug hunters could expand into pen testing, with the caveat that AI is “changing that too.”
Thomas said that whenever bug bounty hunters use AI in their work, it’s crucial they prioritize accuracy to spare humans from having to sort through false positives or spend too much time re-reviewing code.
Bugging out. But some experts are more optimistic about bug hunting’s future in the era of AI. Dave Gerry, CEO of Bugcrowd, a bug-bounty platform, told IT Brew that AI has empowered bug hunters to look for bugs at a “scale and a speed that we’ve just never seen before.”
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
Other times, AI could be the reason behind poor bug bounty submissions. For example, Apple’s bug review system reportedly saw a high volume of “AI slop” or poor-quality submissions from those using AI.
Bugcrowd’s bounty hunters hail from various walks of life; just over half are aged 18 to 24, according to the company’s 2026 “Inside the Mind of a Hacker” report. Gerry told IT Brew that one of the fastest-growing bug-hunting cohorts is under 18. The company doesn’t use outbound marketing to attract people to the platform, but in the past has gone to gamer chatrooms and Reddit channels to recruit.
Bugcrowd isn’t the only bug-hunting company that allows minors, with some stipulations, to offer their bug bounty services to different organizations. HackerOne also allows children above 13 to participate in its bug bounty program, although they must claim their bounties through a parent or legal guardian.
Gerry said kids involved in bug hunting are better at new attack vectors like prompt injection, as well as leveraging AI as part of their workflows.
“Hackers have always…done a great job at automation and scripting,” Gerry said. “The kids today are AI-native, they understand prompt injection, they understand how to build an AI harness to do their work.”
About the author
Caroline Nihill
Caroline Nihill is a reporter for IT Brew who primarily covers cybersecurity and the way that IT teams operate within market trends and challenges.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.