2026 AI Repricing Edition. What actually happened to vulnerability prices between January 2025 and July 2026.
The thesis in one sentence. AI did not make bugs cheaper; it made one tier of bug cheaper, and between January 2025 and July 2026 the market sorted itself along exactly that line, cutting prices where machines now compete and raising them where machines still cannot go.
Casey Ellis, July 28, 2026. Companion to the 2026 evidence edition, which sets out the four pricing objects this edition depends on. Data: bounty-repricing-2026.json and bounty-universe-sample.json. Earlier editions: 2022 · 2022-revised · 2022-v2 · 2026 synthesis · interactive model.
Between January 2025 and July 2026, a long list of vulnerability reward programs changed their prices or their doors. Read as a list, it looks like a retreat. Read by which bugs moved, it is not a retreat at all. It is a sorting.
| Date | Who | What changed | AI named? |
|---|---|---|---|
| 2026-01-31 | curl | Bounty terminated. Lifetime: more than $100,000 paid across 87 confirmed vulnerabilities since 2019. Now $0. org's own | Yes |
| 2026-03-27 | Internet Bug Bounty | Submissions paused. multi | Yes |
| 2026-04-22 | Nextcloud | Monetary rewards discontinued, program continues unpaid. multi | Yes |
| 2026-04-30 | Google Chrome VRP | Renderer RCE and arbitrary read/write bonuses retired. Full-chain reward held at up to $250,000. offer org's own | Yes |
| 2026-05-18 | Internet Bug Bounty | Reward table cut 76 to 89 percent across all severities. single | No |
| 2026-07-27 | GitHub | Public tier fixed at Low $250 / Medium $2,000 / High $5,000 / Critical $10,000. offer org's own | Yes |
| Date | Who | What changed | AI named? |
|---|---|---|---|
| 2025-03-28 | OpenAI | Security bounty maximum $20,000 to $100,000. offer multi | No |
| 2025-10-10 | Apple | Top chain award $1,000,000 to $2,000,000, and in excess of $5,000,000 with bonuses. offer org's own | No, never mentioned |
| 2026-03-16 | Anthropic | Model safety bounty maximum $15,000 to $35,000. offer org's own | Yes |
| 2026-04 | Microsoft | Zero Day Quest pool $4M to $5M; $2,300,000 actually awarded. paid org's own | Yes |
| 2026-04-30 | Google Android VRP | Zero-click Titan M2 full chain with persistence, $1,000,000 to $1,500,000. offer org's own | Yes |
| 2026-07-09 | OpenAI | Bio bounty universal jailbreak $25,000 to $50,000. offer single | Yes |
Every price that fell was attached to a finding a competent automated tool can now produce. Every price that rose was attached to a full chain against a hardened target, or to a class of AI misbehaviour nobody can reliably produce at all. The dates interleave. This is one event, not two.
And the aggregate numbers point the other way from the headlines. Google paid $17.1 million paid org's own across its programs in 2025, an all-time high and more than 40 percent up on 2024. Microsoft paid a record $17 million paid org's own in its FY2025. HackerOne paid $81 million paid org's own in its reporting year, up 13 percent. Meta's payouts rose 74 percent year on year. The money going into this market grew while the per-bug price of the cheap tier collapsed. Any account of 2026 that describes the defensive market as simply retreating has to explain those four numbers.
On 30 April 2026 Google published a single blog post, by three named authors, that cut one reward and raised another and explained both by reference to what AI can and cannot do. Everything else in this edition is corroboration.
Here is Google retiring the Chrome bonuses:
“Last year, we noticed a scarcity of reports demonstrating renderer code execution (RCE), so we introduced an enhanced reward for arbitrary read/write (R/W) and RCE vulnerabilities. This successfully encouraged a wave of new submissions. Today, AI has made demonstrating these techniques almost routine, allowing us to focus on more complex, novel escalation methods. As a result, we are retiring these specific special bonuses.”
And here, in the same post, is Google raising the Android ceiling to $1.5 million and saying why:
“We are revising our program scope to emphasize categories that represent the highest risk to our users. We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents.”
This is unusually clean evidence. Normally the economist has to infer a mechanism from a price move. Here the buyer published the mechanism alongside the move, and the move goes in both directions at once, which rules out the simplest confounder: a firm that merely wanted to spend less would not raise its top tier by fifty percent in the same breath.
The post closes with the sentence that should be pinned to every write-up of the 2026 bounty cuts:
“While these adjustments may reduce the payout for a single bug report, we continue to prioritize our VRPs and the total aggregate rewards paid out in 2026 is expected to increase.”
Unit price down. Aggregate up. That is what a supply shock looks like from the buyer's side, and it is not what a retreat looks like.
The whole argument rests on one distinction, so it is worth being pedantic about it. Finding a memory-safety bug in open-source C is not the same activity as building a reliable exploit chain against a hardened target. As of July 2026 the first is solved and cheap. The second is not.
A consultant-day costs orders of magnitude more than $48. If you are buying that class of finding, your reservation price just moved a long way, and the price you had been offering was set in a world that no longer exists.
The strongest hardened-target evidence is a vendor's self-report about its own withheld model, which is the weakest evidence class there is, and it cannot be independently tested because the model is not available. Public benchmarks say 10 to 22 percent; one unverifiable source says considerably more. If that source is right and the capability generalises, the sorting described in this edition is temporary and the wall moves. That is the single largest uncertainty on this page, and it is unresolved.
The evidence edition prices four objects, not one: the defect, the primitive, the chain, and access. AI did not act on “vulnerabilities”. It acted on those four objects, at different times, by different amounts, and the 2026 price moves land exactly where that predicts.
| Object | What AI did to it | What happened to the price |
|---|---|---|
| Defect a bug, unproven | Production cost collapsed to near zero for both real and spurious claims. Duplication rose sharply because many people run the same tools over the same code. | Fell to zero. curl, Nextcloud, the Internet Bug Bounty. Google stripped rewards from lower OSS tiers. |
| Primitive a proven capability | Demonstration became, in Google's own word, routine. Measured at roughly $48 per bug in open-source C. | Cut. Chrome's renderer RCE and arbitrary read/write bonuses retired. GitHub's public tier halved. |
| Chain a reliable end-to-end exploit | Not crossed. 10 to 22 percent on benchmarks; roughly zero on hard targets; kernel RCE held even against the strongest system tested. | Rose. Apple to $2,000,000. Android Titan M2 to $1,500,000. Chrome's own full-chain reward held at $250,000. |
| Access durable presence | Untouched. Access is bought from operators, not from finders, and no bounty program buys it at all. | No movement attributable to AI. Published broker lists are flat or were cut before the wave, and none has added an AI category. See Section 5. |
This also explains the thing that reads as a paradox in the press coverage: programs cutting prices and raising them at the same time, and total spend rising while per-bug prices fall. Those are not contradictions once you stop treating “a bug” as one commodity.
In July 2026, Chrome published 433 CVEs against 11 in the same month a year earlier, and roughly 401 of them were found internally by Google single. Read that as an economics fact rather than a security one. A bug bounty is a procurement channel, and its price is bounded by the buyer's cost of producing the same good in-house. When the vendor's own agents start finding the commodity tier at scale, the external researcher is no longer the cheapest source, and the bounty price falls for reasons that have nothing to do with report quality.
The interactive model already has a dial for this. It is called substitution, and it has been in the framework since 2022. What is new is not the force; it is that the buyer moved onto the supply side of its own market.
If AI had genuinely collapsed the cost of producing exploits, the market that only ever buys finished exploits should have repriced first and hardest. It is the natural control for this whole argument. Reading the published lists directly on 28 July 2026 produced a result that contradicts the received view in both directions.
Trade coverage through 2026 routinely reports that Crowdfense pays up to $9 million. That page has not existed since March 2025. Between the snapshots of 15 and 30 March 2025, Crowdfense cut its headline ceiling from $9,000,000 to $7,000,000, deleted its two highest tiers entirely (SMS/MMS full-chain zero-click at $7M to $9M, and Mobile App at $5M), halved virtualisation from $1,000,000 to $500,000, and dropped desktop from $2,000,000 to $1,500,000 multi. The list has not moved in the sixteen months since, while the company kept publishing research through June 2026. The freeze is a choice, not neglect.
The full picture from the primary sources org's own:
/program.html now returns 404. It no longer functions as a public price-setter.Note carefully what this does not say. Crowdfense's cut lands in March 2025, roughly a year before the defensive repricing wave, and carries no AI rationale at all. Reading it as an AI effect would be exactly the error this edition is trying to avoid. What the control establishes is narrower and more useful: across the sixteen months in which the defensive market repriced loudly and repeatedly blamed AI, the market that buys finished chains did not respond to AI in any observable way.
Two readings survive, and both are interesting. Either AI has not changed what it costs to produce a chain against a hardened target, which is what the benchmark evidence in Section 3 says. Or offensive prices were never set by discovery cost at all, and are set instead by buyer demand, scarcity, and the willingness of a small number of sovereign customers to pay. The evidence supports the second reading more than most people expect.
Two first-party datapoints, both from 2026, both pointing the same way as Section 3.
When AI finally turned up in a real attack, it turned up at the logic-flaw tier in open-source software: precisely the tier the defensive market has been cutting, and nowhere near the memory-corruption mobile chains that command five to seven million dollars. The offense side and the defence side are describing the same capability boundary from opposite sides of it.
The Williams prosecution, sentenced February 2026 org's own, is the rare case where the inside of a transaction is visible, and it complicates every published figure on this page. He was contracted for $4,000,000 across seven components after an initial sale at $240,000, and realised $1,300,000. Contracted price and realised payment diverge roughly threefold, so a single price-per-exploit number is a category error. The record also confirms that the deals involved “additional periodic payments for follow-on support”: exploit sales are subscriptions with maintenance, which this paper's maintenance force has always assumed and could not previously cite from a court document.
And the sharpest number in either corpus: $35,000,000 of admitted loss across eight components implies roughly $4,400,000 to develop each one at a top-tier Western contractor, against $162,500 realised on distressed grey-market resale. A 27-fold gap between what it costs to build a chain and what a cornered seller gets for one. If AI were collapsing chain production costs, that build-side number is where it would show up first.
There is a third piece of evidence hiding in Apple's October 2025 announcement. Apple raised its top award to $2,000,000 and, across the entire post, never mentions AI once. Its stated reason is mercenary spyware:
“the most advanced adversaries will continue to evolve their techniques. As a result, we're adapting Apple Security Bounty to encourage highly advanced research on our most critical attack surfaces despite the increased difficulty”
The largest defensive raise of the period is priced against the offensive market's bid, not against discovery economics. The defensive ceiling is downstream of the offensive one. That is the oldest claim in this paper and it just got a first-party confirmation from the vendor with the most to lose by saying it.
While the four existing objects were being resorted, a fifth appeared: the vulnerability that exists only because a model is in the loop. The striking thing is not what it costs. It is that almost nobody will name a price at all.
Read the exclusions rather than the headlines:
The economics are legible once stated. A defect you cannot fully close, that recurs in unbounded variations, and that produces no durable capability is uninsurable: paying per instance means paying forever for something you cannot retire. So the classes that cannot be closed get moved out of the price system entirely, into venues that pay for deterrence rather than remediation. Anthropic pays up to $35,000 for a novel universal jailbreak, invite-only. OpenAI pays $50,000 for one specific biosafety universal jailbreak. Those are not defect prices. They are prices for an existence proof.
Two details make the point sharper. First, the classes the model owners refuse to price are picked up by third parties: Mozilla's 0DIN pays up to $15,000 for jailbreaks and prompt injection across models it does not own, and the single largest purse in AI security research, roughly $171,800, was funded by a government AI safety institute rather than by any vendor. When the party bearing the risk will not pay and an outside party will, the market is disagreeing with itself about who the vulnerability belongs to.
Second, and most telling for a paper about the offensive market: CVE-2025-32711, a zero-click prompt-injection data exfiltration in Microsoft 365 Copilot, was real, remotely triggered, assigned a CVE and patched. No exploit broker assigns a standing price to that class. An AI-native vulnerability can be entirely real and still be worth nothing to the buyers who pay the most for capability, because it is patchable by a prompt change, non-persistent and unreliable. It fails every property that makes an exploit an asset.
The sorting account above is not the only story that fits these facts, and several of the alternatives are strong. Presenting them weakly would be a way of not testing the argument, so here they are at their best.
Bounty spend is discretionary operating expense. In a flat-budget year, “AI slop forced our hand” is a far more comfortable line than “we cut a line item”. This is close to unfalsifiable from outside the organisation, which is exactly why it deserves top billing rather than a footnote. The strongest supporting datapoint is not even an AI story: Immunefi's average critical payout fell about 45 percent in 2025 thin with no AI attribution at all, over a period when the underlying asset rose. Budget cycles do independent work that AI narratives can absorb.
This one is dangerous because it is also an AI story and it explains the same evidence without needing any claim about capability tiers. Google states it directly: per-bug payouts down, aggregate expected to rise. HackerOne logged valid AI-asset reports up more than 200 percent and autonomous-agent reports validating at about 49 percent, which is roughly the historical human rate. If supply of genuinely valid findings rose and budgets did not, the price falls by pure mechanics. The sorting account and the volume account are not mutually exclusive, and the volume account needs less machinery.
Linus Torvalds described the kernel security list as “almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools” multi. Django's own account names duplicates and already-fixed issues, not fabrications. A top hunter reports a model finding roughly ten bugs overnight of which about half were duplicates. If AI raises the rediscovery rate, every exploit's expected life shortens and its price falls, and that is a mechanism this paper has priced since 2022. It requires no new theory at all.
Seth Larson was writing about hallucinated security reports to CPython in December 2024. Daniel Stenberg published his numbers in July 2025. The wave of cuts lands in 2026. A two-year lag between a stated cause and its claimed effect needs explaining, and “budgets tightened in 2026” explains it more simply than anything in Section 4.
The sharpest single piece of evidence against a pure-AI account comes from the most-cited victim of AI slop. Stenberg on why reports flooded in: “We suspect the idea of getting money for it is a big part of the explanation.” And after curl removed the bounty, he reported the inflow had “dried out substantially”. If removing the reward removes the flood, the flood was a response to the reward, and AI merely lowered the cost of answering it. Note also that curl's payouts totalled only about $100,000 over seven years: the bounty was never the expensive part, so cutting it cannot have been a cost-saving measure.
Private and invite-only programs have been the majority of platform activity since the industry's early days. On HackerOne's own published figures, private programs were 92 percent of its bounty programs in 2016, 88 percent in 2017 and 79 percent in 2018 org's own, with roughly 80 percent cited more recently. The funnel was mostly closed before any of this, and no published 2025 or 2026 platform statistic shows the private share rising because of AI. GitHub's VIP tier is a well-documented instance of a twelve-year-old pattern, not a new invention. In the interest of full disclosure, I helped popularise that pattern; that is a reason to be careful about calling it novel, not a reason to omit it.
In July 2025 I told TechCrunch that AI had not yet caused a significant spike in low-quality reports on Bugcrowd, and that submission quality was “not any better or worse”. Volume was up; quality, at that point, was not visibly down. A year later the picture is different in some places and still looks like that in others, and the programs that held steady are as informative as the ones that cut. Anyone using this edition should weight that 2025 statement as a prior that the 2026 evidence has partially, but not wholly, overturned.
A claim that cannot be killed is not worth making. Here is what would kill this one.
The last one is worth watching closely. GitHub changed one variable, on a known date, on a program with a published before and after. If the intervention does not move signal, the stated rationale across this entire period gets substantially weaker.
This edition ships two machine-readable files. Neither is a clean sample, and the difference between them matters.
bounty-repricing-2026.json holds 33 rows of program price and access changes, each with an evidence tier, a source URL and, where the organisation stated one, a verbatim reason. It is assembled from announcements and press, so it inherits an obvious bias: a program raising its payouts is rarely news, while a program cutting them reliably is. Counting rows in that file cannot tell you the direction of the market, and the file says so in its own metadata.
To get at direction, bounty-universe-sample.json takes a different approach: a fixed list of 28 programs declared before any result was seen, each of which publishes a numeric reward table, compared against its own archived page from the start of 2026. Of the 28, only 8 resolved. Most reward tables are rendered by JavaScript, or are absent from the archive, and a fetch that returns nothing is a fact about the method rather than a fact about the program. Among the rows that did resolve, seven were unchanged and one moved, and the one that moved is within the noise of the extraction method.
GitHub's page reads $30,000 as its maximum both before and after the restructure. By the measure “highest number on the page”, nothing happened on 27 July 2026. But the public ceiling fell from roughly $30,000 to $10,000 and the old ceiling moved behind an invitation. The headline price did not move; the population who can reach it did. Any analysis that tracks published maxima will miss this entire event, which is a decent argument that published maxima are the wrong instrument and that access terms deserve to be a first-class field in vulnerability price data.
One more piece of counter-evidence deserves its own line, because it is the cleanest disconfirmation available. Facing the same wave, Mozilla cut nothing. It named the identical problem, that “reports that look plausibly correct but are wrong impose an asymmetric cost on project maintainers”, then built verification tooling and invited an AI lab to submit model-found issues in bulk. Same input, opposite output. Whatever the 2026 repricing is, it is not deterministic.
Every figure on this page traces to one of these. Full per-row citations, evidence tiers, archive notes and verbatim stated reasons are in the JSON corpus.