2026 AI Repricing Edition. What actually happened to vulnerability prices between January 2025 and July 2026.
The thesis, stated at the strength the evidence actually supports. AI made one tier of bug much cheaper to find and has not yet touched the others. One buyer, Google, repriced in both directions on a single day and said that was why. Several other programs cut exactly the tiers where machine-generated reports land. But the raises mostly sit on ceilings almost nobody ever collects, and the only sample declared in advance says most programs did nothing at all. This is a well-documented case study with consistent corroboration, not a market-wide natural experiment, and Section 9 sets out where it is thin.
Casey Ellis, July 28, 2026. Companion to the 2026 evidence edition, which sets out the four pricing objects this edition depends on. Data: bounty-repricing-2026.json and bounty-universe-sample.json. Earlier editions: 2022 · 2022-revised · 2022-v2 · 2026 synthesis · interactive model.
Between January 2025 and July 2026, a long list of vulnerability reward programs changed their prices or their doors. Read as a list, it looks like a retreat. Read by which bugs moved, it is not a retreat at all. It is a sorting.
| Date | Who | What changed | AI named? |
|---|---|---|---|
| 2026-01-31 | curl | Bounty terminated. Lifetime: more than $100,000 paid across 87 confirmed vulnerabilities since 2019. Now $0. org's own | Yes |
| 2026-03-27 | Internet Bug Bounty | Submissions paused. multi | Yes |
| 2026-04-22 | Nextcloud | Monetary rewards discontinued, program continues unpaid. multi | Yes |
| 2026-04-30 | Google Chrome VRP | Renderer RCE and arbitrary read/write bonuses retired. Full-chain reward held at up to $250,000. offer org's own | Yes |
| 2026-05-18 | Internet Bug Bounty | Reward table cut 76 to 89 percent across all severities. single | No |
| 2026-07-27 | GitHub | Public tier fixed at Low $250 / Medium $2,000 / High $5,000 / Critical $10,000. offer org's own | Yes |
| Date | Who | What changed | AI named? |
|---|---|---|---|
| 2025-03-28 | OpenAI | Security bounty maximum $20,000 to $100,000. offer multi | No |
| 2025-10-10 | Apple | Top chain award $1,000,000 to $2,000,000, and in excess of $5,000,000 with bonuses. offer org's own | No, never mentioned |
| 2026-03-16 | Anthropic | Model safety bounty maximum $15,000 to $35,000. offer org's own | Yes |
| 2026-04 | Microsoft | Zero Day Quest pool $4M to $5M; $2,300,000 actually awarded. paid org's own | Yes |
| 2026-04-30 | Google Android VRP | Zero-click Titan M2 full chain with persistence, $1,000,000 to $1,500,000. offer org's own | Yes |
| 2026-07-09 | OpenAI | Bio bounty universal jailbreak $25,000 to $50,000. offer single | Yes |
I founded Bugcrowd in 2012 and hold no current operational role there. Bugcrowd, HackerOne and their competitors appear on this page wherever a primary source exists and are described only to what that source supports. Where I have been publicly wrong about this subject, it is quoted verbatim in Section 7.
Every price cut that carried a stated AI rationale was attached to a finding a competent automated tool can now produce. Every price that rose was attached to a full chain against a hardened target, or to a class of AI misbehaviour nobody can reliably produce at all. The dates interleave.
The exception, stated here rather than buried in the data: the single largest percentage cut in this whole period, the Internet Bug Bounty's 76 to 89 percent table reduction in May 2026, was not attributed to AI at all. The statement accompanying it pointed at the programme's own funding mechanism, under which bounty levels adjust automatically with sponsor contributions. That came weeks after the earlier submissions pause was attributed to AI. (The Internet Bug Bounty is administered on HackerOne but is sponsor-funded and separately governed, so this is a statement about the programme rather than about the platform.) It sits in the cut table above marked "AI named? No" and it does not support the argument on this page. Any account of 2026 has to carry it, including this one.
And the aggregate numbers point the other way from the headlines. Google paid $17.1 million paid org's own across its programs in 2025, an all-time high and more than 40 percent up on 2024. Microsoft paid a record $17 million paid org's own in its FY2025. HackerOne paid $81 million paid org's own in its reporting year, up 13 percent. Meta's payouts rose 74 percent year on year. The money going into this market grew while the per-bug price of the cheap tier collapsed. Any account of 2026 that describes the defensive market as simply retreating has to explain those four numbers.
On 30 April 2026 Google published a single blog post, by three named authors, that cut one reward and raised another and explained both by reference to what AI can and cannot do. Everything else in this edition is corroboration.
Here is Google retiring the Chrome bonuses:
“Last year, we noticed a scarcity of reports demonstrating renderer code execution (RCE), so we introduced an enhanced reward for arbitrary read/write (R/W) and RCE vulnerabilities. This successfully encouraged a wave of new submissions. Today, AI has made demonstrating these techniques almost routine, allowing us to focus on more complex, novel escalation methods. As a result, we are retiring these specific special bonuses.”
And here, in the same post, is Google raising the Android ceiling to $1.5 million and saying why:
“We are revising our program scope to emphasize categories that represent the highest risk to our users. We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents.”
This is unusually clean evidence of a stated mechanism. Normally the economist has to infer why a price moved. Here the buyer published its reasoning alongside the move, and the move goes in both directions at once.
It does not, however, rule out the budget explanation, and it is worth being explicit about why. An earlier draft of this page argued that a firm which merely wanted to spend less would not raise its top tier by fifty percent in the same breath. That argument does not survive contact with Section 9. Announced ceilings are mostly fiction: Google's largest single reward actually paid in 2025 was $250,000, against announced ceilings six times larger, and Apple notes no successful Gatekeeper or broad iCloud exploit has ever been demonstrated. So the cuts land on tiers where cheques are genuinely written at volume, and the raises land on ceilings that have rarely or never been collected. Cutting there costs real money and raising here is close to free. A pure cost-control strategy predicts this exact pattern, with the AI framing as favourable packaging.
What the post does establish is narrower and still worth having: the buyer named automated tooling as the discriminator, in both directions, in public, on the record. Whether that reason is the operative cause or the best available justification is not resolvable from a blog post, and the test that would resolve it does not exist yet. It is a realised-payout-by-tier series: if chain-tier payouts actually rose while defect-tier payouts fell, the sorting is real in money rather than in offers. Nobody publishes that, which is why Rival 1 in Section 7 is the strongest competitor to this whole account and is presented first.
The post closes with a sentence that most coverage of the 2026 cuts left out:
“While these adjustments may reduce the payout for a single bug report, we continue to prioritize our VRPs and the total aggregate rewards paid out in 2026 is expected to increase.”
Unit price down. Aggregate up. That is what a supply shock looks like from the buyer's side, and it is not what a retreat looks like.
The whole argument rests on one distinction, so it is worth being pedantic about it. Finding a memory-safety bug in open-source C is not the same activity as building a reliable exploit chain against a hardened target. As of July 2026 the first is commoditised. The second is not.
Finding memory-safety bugs in open-source C has been cheap since coverage-guided fuzzing industrialised it around 2016. OSS-Fuzz has surfaced tens of thousands of them, and FFmpeg in particular is a famously bug-dense target whose maintainers spent late 2025 in a public argument with Google about the burden of exactly this class of low-severity machine-found report. Anyone presenting $48 per bug as the arrival of cheap discovery is about a decade late.
The delta AI actually added is narrower and more specific: writing the harness rather than running it (AI-generated fuzz targets reached code that human-written harnesses never covered, which is how a roughly 20-year-old OpenSSL flaw surfaced), and reaching classes fuzzers structurally cannot find, in particular semantic and logic flaws. That is the capability that moved, and it is the one the price data responds to.
A consultant-day costs orders of magnitude more than $48. If you are buying that class of finding, your reservation price just moved a long way, and the price you had been offering was set in a world that no longer exists.
The strongest hardened-target evidence is a vendor's self-report about its own withheld model, which is the weakest evidence class there is, and it cannot be independently tested because the model is not available. Public benchmarks say 10 to 22 percent; one unverifiable source says considerably more. If that source is right and the capability generalises, the sorting described in this edition is temporary and the wall moves. That is the single largest uncertainty on this page, and it is unresolved.
The evidence edition prices four objects, not one: the defect, the primitive, the chain, and access. AI did not act on “vulnerabilities”. It acted on those four objects, at different times, by different amounts, and the 2026 price moves land exactly where that predicts.
| Object | What AI did to it | What happened to the price |
|---|---|---|
| Defect a bug, unproven | Production cost collapsed to near zero for both real and spurious claims. Duplication rose sharply because many people run the same tools over the same code. | Fell to zero. curl, Nextcloud, the Internet Bug Bounty. Google stripped rewards from lower OSS tiers. |
| Primitive a proven capability | Demonstration became, in Google's own word, routine. Measured at roughly $48 per bug in open-source C. | Cut. Chrome's renderer RCE and arbitrary read/write bonuses retired. GitHub's public tier cut by two thirds or more at the top severities (critical roughly $30,000 to $10,000, high $20,000 to $5,000). |
| Chain a reliable end-to-end exploit | Not crossed. 10 to 22 percent on benchmarks; roughly zero on hard targets; kernel RCE held even against the strongest system tested. | Rose. Apple to $2,000,000. Android Titan M2 to $1,500,000. Chrome's own full-chain reward held at $250,000. |
| Access durable presence | Untouched. Access is bought from operators, not from finders, and no bounty program buys it at all. | No movement attributable to AI. Published broker lists are flat or were cut before the wave, and none has added an AI category. See Section 5. |
This also explains the thing that reads as a paradox in the press coverage: programs cutting prices and raising them at the same time, and total spend rising while per-bug prices fall. Those are not contradictions once you stop treating “a bug” as one commodity.
I assigned each price move to one of the four objects after I knew which direction it went, using my own judgement and no pre-registered coding rule. That is exactly the setup in which a framework absorbs whatever it is shown, and there are two events in the corpus where the coding is genuinely arguable rather than obvious.
The Internet Bug Bounty's cut covered all severities including criticals in core internet infrastructure, which is not obviously the defect tier; I coded it defect. GitHub's restructure cut a public critical ceiling, which is chain-adjacent; I coded it mixed and cite it under the primitive line. A hostile reader is entitled to say those two were filed where they fit the argument. Eleven of the 39 rows carry mixed or ai-behaviour, and a category that can absorb any inconvenient case is not doing analytical work. The fix is a coding rule stated in advance, applied by someone blind to the direction of each move, with the disagreement rate published. That has not been done, and until it is, this table is an interpretation rather than a measurement.
In July 2026, Chrome reportedly published 433 CVEs against 11 in the same month a year earlier, with roughly 401 found internally by Google single. Treat that pair of numbers with care: 11 is anomalously low for a Chrome month and 433 anomalously high, which is the signature of a bulk CVE-assignment or CNA bookkeeping change as much as of a genuine forty-fold surge in discovery. It is single-sourced and unverified against Chrome's release notes. The argument below does not depend on it, and stands on Big Sleep and OSS-Fuzz alone; the July figures would only make it vivid. The economic reading matters as much as the security one. A bug bounty is a procurement channel, and its price is bounded by the buyer's cost of producing the same good in-house. When the vendor's own agents start finding the commodity tier at scale, the external researcher is no longer the cheapest source, and the bounty price falls for reasons that have nothing to do with report quality.
The interactive model already has a dial for this. It is called substitution, and it has been in the framework since 2022. What is new is not the force; it is that the buyer moved onto the supply side of its own market.
If AI had genuinely collapsed the cost of producing exploits, the market that only ever buys finished exploits should have repriced first and hardest. It is the natural control for this whole argument. Reading the published lists directly on 28 July 2026 produced a result that contradicts the received view in both directions.
Trade coverage through 2026 routinely reports that Crowdfense pays up to $9 million. That page has not existed since March 2025. Between the snapshots of 15 and 30 March 2025, Crowdfense cut its headline ceiling from $9,000,000 to $7,000,000, deleted its two highest tiers entirely (SMS/MMS full-chain zero-click at $7M to $9M, and Mobile App at $5M), halved virtualisation from $1,000,000 to $500,000, and dropped desktop from $2,000,000 to $1,500,000 multi. The list has not moved in the sixteen months since, while the company kept publishing research through June 2026. The freeze is a choice, not neglect.
The full picture from the primary sources org's own:
/program.html now returns 404. It no longer functions as a public price-setter.Note carefully what this does not say. Crowdfense's cut lands in March 2025, roughly a year before the defensive repricing wave, and carries no AI rationale at all. Reading it as an AI effect would be exactly the error this edition is trying to avoid. What the control establishes is narrower and more useful: across the sixteen months in which the defensive market repriced loudly and repeatedly blamed AI, the market that buys finished chains showed no AI-attributed response in any surviving public price list.
That phrasing is deliberately weaker than "the offensive market did not move", for two reasons that cut against this section. First, the instrument partly died during the observation window: Zerodium stopped publishing in February 2025 and Crowdfense froze in March 2025, so a market whose public price signalling went dark early in the period cannot show you much of anything afterwards, and withdrawing a price list is itself a response to something. Second, published lists are marketing artifacts, and the Williams record below shows contracted and realised prices diverging roughly threefold, so actual transaction prices are invisible to this instrument entirely. A control that cannot see the thing it controls for is weak evidence, and it is the weakest link in this edition's argument.
Two readings survive, and both are interesting. Either AI has not changed what it costs to produce a chain against a hardened target, which is what the benchmark evidence in Section 3 says. Or offensive prices were never set by discovery cost at all, and are set instead by buyer demand, scarcity, and the willingness of a small number of sovereign customers to pay. The evidence supports the second reading more than most people expect.
Two first-party datapoints, both from 2026, both pointing the same way as Section 3.
When AI finally turned up in a real attack, it turned up at the logic-flaw tier in open-source software: precisely the tier the defensive market has been cutting, and nowhere near the memory-corruption mobile chains that command five to seven million dollars. The offense side and the defence side are describing the same capability boundary from opposite sides of it.
The Williams prosecution, sentenced February 2026 org's own, is the rare case where the inside of a transaction is visible, and it complicates every published figure on this page. He was contracted for $4,000,000 across seven components after an initial sale at $240,000, and realised $1,300,000. Contracted price and realised payment diverge roughly threefold, so a single price-per-exploit number is a category error. The record also confirms that the deals involved “additional periodic payments for follow-on support”: exploit sales are subscriptions with maintenance, which this paper's maintenance force has always assumed and could not previously cite from a court document.
And the sharpest number in either corpus, taking the government's loss figure at face value, which is a real caveat because sentencing-loss calculations are the victim's asserted value and are routinely maximised: $35,000,000 across eight components implies roughly $4,400,000 to develop each one at a top-tier Western contractor, against $162,500 realised on distressed grey-market resale. A 27-fold gap between what it costs to build a chain and what a cornered seller gets for one. If AI were collapsing chain production costs, that build-side number is where it would show up first.
There is a third piece of evidence hiding in Apple's October 2025 announcement. Apple raised its top award to $2,000,000 and, across the entire post, never mentions AI once. Its stated reason is mercenary spyware:
“the most advanced adversaries will continue to evolve their techniques. As a result, we're adapting Apple Security Bounty to encourage highly advanced research on our most critical attack surfaces despite the increased difficulty”
The largest defensive raise of the period is priced against the offensive market's bid, not against discovery economics. The defensive ceiling is downstream of the offensive one. That is not a new observation and it is not mine: Katie Moussouris built Microsoft's programme on the principle that a vendor cannot outbid the offence market and should not try, and she and others have been making the point since the first vendor programmes. What is new here is the first-party confirmation, from the vendor with the most to lose by saying it out loud.
While the four existing objects were being resorted, a fifth appeared: the vulnerability that exists only because a model is in the loop. The striking thing is not what it costs. It is that almost nobody will name a price at all.
Read the exclusions rather than the headlines:
The economics follow from a distinction worth making carefully, because it is easy to state contradictorily. Individual instances patch; the class does not close. Any given prompt injection can be fixed, often server-side and quickly. But the class recurs in unbounded variations, so paying per instance means paying forever for something that can never be retired, and no insurer or budget owner underwrites that. So the classes that cannot be closed get moved out of the price system entirely, into venues that pay for deterrence rather than remediation. Anthropic pays up to $35,000 for a novel universal jailbreak, invite-only. OpenAI pays $50,000 for one specific biosafety universal jailbreak. Those are not defect prices. They are prices for an existence proof.
Two details make the point sharper. First, the classes the model owners refuse to price are picked up by third parties: Mozilla's 0DIN pays up to $15,000 for jailbreaks and prompt injection across models it does not own, and the single largest purse in AI security research, roughly $171,800, was funded by a government AI safety institute rather than by any vendor. When the party bearing the risk will not pay and an outside party will, the market is disagreeing with itself about who the vulnerability belongs to.
Second, and most telling for a paper about the offensive market: CVE-2025-32711, the zero-click prompt-injection data exfiltration in Microsoft 365 Copilot, was real, remotely triggered, assigned a CVE and patched. It was not a trivial finding either: the reported chain defeated prompt-injection classifiers, link redaction and content-security policy. No exploit broker assigns a standing price to that class. An AI-native vulnerability can be entirely real, genuinely clever, and still be worth nothing to the buyers who pay the most for capability, because it was patchable server-side without touching a single customer system, it is non-persistent, and it is unreliable. It fails every property that makes an exploit an asset: you cannot hold it, you cannot depend on it, and the vendor can retire your copy without your knowledge.
The sorting account above is not the only story that fits these facts, and several of the alternatives are strong. Presenting them weakly would be a way of not testing the argument, so here they are at their best.
Bounty spend is discretionary operating expense. In a flat-budget year, “AI slop forced our hand” is a far more comfortable line than “we cut a line item”. This is close to unfalsifiable from outside the organisation, which is exactly why it deserves top billing rather than a footnote. The strongest supporting datapoint is not even an AI story: Immunefi's average critical payout fell about 45 percent in 2025 thin with no AI attribution at all, over a period when the underlying asset rose. Budget cycles do independent work that AI narratives can absorb.
This one is dangerous because it is also an AI story and it explains the same evidence without needing any claim about capability tiers. Google states it directly: per-bug payouts down, aggregate expected to rise. HackerOne logged valid AI-asset reports up more than 200 percent and autonomous-agent reports validating at about 49 percent, which is roughly the historical human rate. If supply of genuinely valid findings rose and budgets did not, the price falls by pure mechanics. The sorting account and the volume account are not mutually exclusive, and the volume account needs less machinery.
Linus Torvalds described the kernel security list as “almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools” multi. Django's own account names duplicates and already-fixed issues, not fabrications. A top hunter reports a model finding roughly ten bugs overnight of which about half were duplicates. If AI raises the rediscovery rate, every exploit's expected life shortens and its price falls, and that is a mechanism this paper has priced since 2022. It requires no new theory at all.
Rivals 2 and 3 look like variations on one idea but they are different mechanisms making opposite predictions, and this page does not adjudicate between them.
Competition says machines now produce genuinely valid findings at the cheap tiers, supply expanded, and the buyer's reservation price fell. Congestion says machines produce plausible-looking noise, triage capacity is the binding constraint, and prices fell wherever the noise landed, with no capability sorting required at all.
They are distinguishable in principle: under competition, validity rates at the cut tiers should hold or rise, while under congestion they collapse. The available evidence splits. HackerOne's autonomous-agent reports validating at about 49 percent, and Meta's reward rate holding flat at roughly 6 percent through a 30 percent volume increase, both point at competition. curl's validity rate falling from above 15 percent to below 5 percent points squarely at congestion. Note also that most of the stated reasons attached to the cut rows are congestion language, not capability language: GitHub's own words are “to reduce the volume of low-effort and AI-generated reports”. The capability-sorting story on this page owns the rows where the buyer named capability, and that is essentially Google. On the rest, congestion explains the same data with less machinery.
Seth Larson was writing about hallucinated security reports to CPython in December 2024. Daniel Stenberg published his numbers in July 2025. The wave of cuts lands in 2026. A two-year lag between a stated cause and its claimed effect needs explaining, and “budgets tightened in 2026” explains it more simply than anything in Section 4.
The sharpest single piece of evidence against a pure-AI account comes from the most-cited victim of AI slop. Stenberg on why reports flooded in: “We suspect the idea of getting money for it is a big part of the explanation.” And after curl removed the bounty, he reported the inflow had “dried out substantially”. If removing the reward removes the flood, the flood was a response to the reward, and AI merely lowered the cost of answering it. Note also that curl's payouts totalled only about $100,000 over seven years: the bounty was never the expensive part, so cutting it cannot have been a cost-saving measure.
Private and invite-only programs have been the majority of platform activity since the industry's early days. On HackerOne's own published figures, private programs were 92 percent of its bounty programs in 2016, 88 percent in 2017 and 79 percent in 2018 org's own, with roughly 80 percent cited more recently. The funnel was mostly closed before any of this, and no published 2025 or 2026 platform statistic shows the private share rising because of AI. GitHub's VIP tier is a well-documented instance of a twelve-year-old pattern, not a new invention. In the interest of full disclosure, I helped popularise that pattern; that is a reason to be careful about calling it novel, not a reason to omit it.
On 24 July 2025 I told TechCrunch, in full: “AI is widely used in most submissions, but it hasn't yet caused a significant spike in low-quality 'slop' reports.” And then: “This'll probably escalate in the future, but it's not here yet.”
Eight months later Bugcrowd published that its queues had risen more than 334 percent in three weeks. So the direction was right and the timing was wrong, which is the more interesting way to be wrong. What the gap says is that the collapse was not a smooth response to gradually improving models: it arrived late, then all at once. A step change like that fits Rival 5 better than it fits the capability-sorting story on this page, because incentive structures break suddenly and capability curves do not. I am citing myself here as evidence against my own thesis, and it should be weighted that way.
A claim that cannot be killed is not worth making. Here is what would kill this one.
The last one is worth watching closely. GitHub changed one variable, on a known date, on a program with a published before and after. If the intervention does not move signal, the stated rationale across this entire period gets substantially weaker.
This edition ships two machine-readable files. Neither is a clean sample, and the difference between them matters.
bounty-repricing-2026.json holds 33 rows of program price and access changes, each with an evidence tier, a source URL and, where the organisation stated one, a verbatim reason. It is assembled from announcements and press, so it inherits an obvious bias: a program raising its payouts is rarely news, while a program cutting them reliably is. Counting rows in that file cannot tell you the direction of the market, and the file says so in its own metadata.
To get at direction, bounty-universe-sample.json takes a different approach: a fixed list of 28 programs declared before any result was seen, each of which publishes a numeric reward table, compared against its own archived page from the start of 2026. Of the 28, only 8 resolved. Most reward tables are rendered by JavaScript, or are absent from the archive, and a fetch that returns nothing is a fact about the method rather than a fact about the program. Among the rows that did resolve, seven were unchanged and one moved, and the one that moved is within the noise of the extraction method.
The only instrument on this page capable of speaking to direction says the modal program did nothing. That is not a footnote to the argument, it is a boundary on it. The sorting described in Sections 1 through 4 characterises the programs that moved, which are disproportionately the ones large enough and public enough to make news. It does not characterise the market.
And the seven "unchanged" verdicts are weaker than they look, because the instrument that produced them is demonstrably blind to the one event it was pointed at (see below). They mean "no change detected by a proxy known to miss real changes", not "no change". Non-resolution is not random either: JavaScript-rendered tables correlate with exactly the large modern programs where the action is claimed, so the resolvable subsample skews toward the static and the quiet. Read honestly, this file establishes that the news is not the market, and very little else.
GitHub's page reads $30,000 as its maximum both before and after the restructure. By the measure “highest number on the page”, nothing happened on 27 July 2026. But the public ceiling fell from roughly $30,000 to $10,000 and the old ceiling moved behind an invitation. The headline price did not move; the population who can reach it did. Any analysis that tracks published maxima will miss this entire event, which is a decent argument that published maxima are the wrong instrument and that access terms deserve to be a first-class field in vulnerability price data.
One more piece of counter-evidence deserves its own line, because it is the cleanest disconfirmation available. Facing the same wave, Mozilla cut nothing. It named the identical problem, that “reports that look plausibly correct but are wrong impose an asymmetric cost on project maintainers”, then built verification tooling and invited an AI lab to submit model-found issues in bulk. Same input, opposite output. Whatever the 2026 repricing is, it is not deterministic.
Every figure on this page traces to one of these. Full per-row citations, evidence tiers, archive notes and verbatim stated reasons are in the JSON corpus.