What Is a Bug Worth When a Machine Found It?

2026 AI Repricing Edition. What actually happened to vulnerability prices between January 2025 and July 2026.

The thesis in one sentence. AI did not make bugs cheaper; it made one tier of bug cheaper, and between January 2025 and July 2026 the market sorted itself along exactly that line, cutting prices where machines now compete and raising them where machines still cannot go.

Casey Ellis, July 28, 2026. Companion to the 2026 evidence edition, which sets out the four pricing objects this edition depends on. Data: bounty-repricing-2026.json and bounty-universe-sample.json. Earlier editions: 2022 · 2022-revised · 2022-v2 · 2026 synthesis · interactive model.

Section 1What actually happened

Between January 2025 and July 2026, a long list of vulnerability reward programs changed their prices or their doors. Read as a list, it looks like a retreat. Read by which bugs moved, it is not a retreat at all. It is a sorting.

org's own the organisation's own announcement, fetched multi multiple independent outlets single one outlet only thin third-party analysis or inference
offer a published ceiling, which may never have been paid paid a disclosed actual payout

Prices that fell, or went to zero

DateWhoWhat changedAI named?
2026-01-31curlBounty terminated. Lifetime: more than $100,000 paid across 87 confirmed vulnerabilities since 2019. Now $0. org's ownYes
2026-03-27Internet Bug BountySubmissions paused. multiYes
2026-04-22NextcloudMonetary rewards discontinued, program continues unpaid. multiYes
2026-04-30Google Chrome VRPRenderer RCE and arbitrary read/write bonuses retired. Full-chain reward held at up to $250,000. offer org's ownYes
2026-05-18Internet Bug BountyReward table cut 76 to 89 percent across all severities. singleNo
2026-07-27GitHubPublic tier fixed at Low $250 / Medium $2,000 / High $5,000 / Critical $10,000. offer org's ownYes

Prices that rose, in the same window

DateWhoWhat changedAI named?
2025-03-28OpenAISecurity bounty maximum $20,000 to $100,000. offer multiNo
2025-10-10AppleTop chain award $1,000,000 to $2,000,000, and in excess of $5,000,000 with bonuses. offer org's ownNo, never mentioned
2026-03-16AnthropicModel safety bounty maximum $15,000 to $35,000. offer org's ownYes
2026-04MicrosoftZero Day Quest pool $4M to $5M; $2,300,000 actually awarded. paid org's ownYes
2026-04-30Google Android VRPZero-click Titan M2 full chain with persistence, $1,000,000 to $1,500,000. offer org's ownYes
2026-07-09OpenAIBio bounty universal jailbreak $25,000 to $50,000. offer singleYes
Read the two tables together

Every price that fell was attached to a finding a competent automated tool can now produce. Every price that rose was attached to a full chain against a hardened target, or to a class of AI misbehaviour nobody can reliably produce at all. The dates interleave. This is one event, not two.

And the aggregate numbers point the other way from the headlines. Google paid $17.1 million paid org's own across its programs in 2025, an all-time high and more than 40 percent up on 2024. Microsoft paid a record $17 million paid org's own in its FY2025. HackerOne paid $81 million paid org's own in its reporting year, up 13 percent. Meta's payouts rose 74 percent year on year. The money going into this market grew while the per-bug price of the cheap tier collapsed. Any account of 2026 that describes the defensive market as simply retreating has to explain those four numbers.

Section 2The one post that contains the whole argument

On 30 April 2026 Google published a single blog post, by three named authors, that cut one reward and raised another and explained both by reference to what AI can and cannot do. Everything else in this edition is corroboration.

Here is Google retiring the Chrome bonuses:

“Last year, we noticed a scarcity of reports demonstrating renderer code execution (RCE), so we introduced an enhanced reward for arbitrary read/write (R/W) and RCE vulnerabilities. This successfully encouraged a wave of new submissions. Today, AI has made demonstrating these techniques almost routine, allowing us to focus on more complex, novel escalation methods. As a result, we are retiring these specific special bonuses.”

And here, in the same post, is Google raising the Android ceiling to $1.5 million and saying why:

“We are revising our program scope to emphasize categories that represent the highest risk to our users. We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents.”
The mechanism, stated by the buyer
Google did not cut its bug bounty. Google repriced two capability tiers in opposite directions, in one announcement, and named automated tooling as the discriminator for both.

This is unusually clean evidence. Normally the economist has to infer a mechanism from a price move. Here the buyer published the mechanism alongside the move, and the move goes in both directions at once, which rules out the simplest confounder: a firm that merely wanted to spend less would not raise its top tier by fifty percent in the same breath.

The post closes with the sentence that should be pinned to every write-up of the 2026 bounty cuts:

“While these adjustments may reduce the payout for a single bug report, we continue to prioritize our VRPs and the total aggregate rewards paid out in 2026 is expected to increase.

Unit price down. Aggregate up. That is what a supply shock looks like from the buyer's side, and it is not what a retreat looks like.

Section 3What AI can and cannot actually do

The whole argument rests on one distinction, so it is worth being pedantic about it. Finding a memory-safety bug in open-source C is not the same activity as building a reliable exploit chain against a hardened target. As of July 2026 the first is solved and cheap. The second is not.

Solved and cheap

depthfirst, 2026
21 previously-unknown zero-days in FFmpeg across 1.5 million lines of C, using commercially available models, for roughly $1,000 of compute. That is about $48 per bug multi. One of the bugs had been latent since 2003.
Google, 2024 to 2025
Big Sleep found a pre-release SQLite bug, then CVE-2025-6965, then 20 more across FFmpeg and ImageMagick. AI-written fuzz harnesses on OSS-Fuzz surfaced 26 vulnerabilities including a roughly 20-year-old OpenSSL flaw multi.

A consultant-day costs orders of magnitude more than $48. If you are buying that class of finding, your reservation price just moved a long way, and the price you had been offering was set in a world that no longer exists.

Not solved

CyberGym, Berkeley
1,507 real-world vulnerabilities across 188 projects. The best configuration reproduces about 22 percent multi of bugs that are known to exist. Seventy-eight percent failure on a task with the answer key available.
CVE-Bench, ICML 2025
Forty critical web-application CVEs requiring actual exploitation: up to 10 percent success in the zero-day setting, 13 percent one-day multi.
Agent evaluations, 2026
One-day exploitation with the advisory supplied in context: 87 percent. Without the advisory: 7 percent single. That gap is the difference between recall and discovery. Hard HackTheBox machines: approximately zero.
The hardest available test
A withheld, cyber-specialised frontier model reported genuine hardened-target results, including a four-vulnerability chain escaping a browser renderer and OS sandbox. It still failed to achieve remote code execution against the Linux kernel single. Defence in depth held.
The honest caveat on this section

The strongest hardened-target evidence is a vendor's self-report about its own withheld model, which is the weakest evidence class there is, and it cannot be independently tested because the model is not available. Public benchmarks say 10 to 22 percent; one unverifiable source says considerably more. If that source is right and the capability generalises, the sorting described in this edition is temporary and the wall moves. That is the single largest uncertainty on this page, and it is unresolved.

Section 4The sorting

The evidence edition prices four objects, not one: the defect, the primitive, the chain, and access. AI did not act on “vulnerabilities”. It acted on those four objects, at different times, by different amounts, and the 2026 price moves land exactly where that predicts.

ObjectWhat AI did to itWhat happened to the price
Defect
a bug, unproven
Production cost collapsed to near zero for both real and spurious claims. Duplication rose sharply because many people run the same tools over the same code.Fell to zero. curl, Nextcloud, the Internet Bug Bounty. Google stripped rewards from lower OSS tiers.
Primitive
a proven capability
Demonstration became, in Google's own word, routine. Measured at roughly $48 per bug in open-source C.Cut. Chrome's renderer RCE and arbitrary read/write bonuses retired. GitHub's public tier halved.
Chain
a reliable end-to-end exploit
Not crossed. 10 to 22 percent on benchmarks; roughly zero on hard targets; kernel RCE held even against the strongest system tested.Rose. Apple to $2,000,000. Android Titan M2 to $1,500,000. Chrome's own full-chain reward held at $250,000.
Access
durable presence
Untouched. Access is bought from operators, not from finders, and no bounty program buys it at all.No movement attributable to AI. Published broker lists are flat or were cut before the wave, and none has added an AI category. See Section 5.
The claim
The 2026 repricing is not a judgement about bug bounties. It is the four pricing objects decoupling, because a general-purpose technology arrived that is very good at two of them and, so far, not good at the other two.

This also explains the thing that reads as a paradox in the press coverage: programs cutting prices and raising them at the same time, and total spend rising while per-bug prices fall. Those are not contradictions once you stop treating “a bug” as one commodity.

A mechanism the coverage has missed: the buyer became a supplier

In July 2026, Chrome published 433 CVEs against 11 in the same month a year earlier, and roughly 401 of them were found internally by Google single. Read that as an economics fact rather than a security one. A bug bounty is a procurement channel, and its price is bounded by the buyer's cost of producing the same good in-house. When the vendor's own agents start finding the commodity tier at scale, the external researcher is no longer the cheapest source, and the bounty price falls for reasons that have nothing to do with report quality.

The interactive model already has a dial for this. It is called substitution, and it has been in the framework since 2022. What is new is not the force; it is that the buyer moved onto the supply side of its own market.

Section 5The control: what the offensive market actually did

If AI had genuinely collapsed the cost of producing exploits, the market that only ever buys finished exploits should have repriced first and hardest. It is the natural control for this whole argument. Reading the published lists directly on 28 July 2026 produced a result that contradicts the received view in both directions.

A correction worth leading with

Trade coverage through 2026 routinely reports that Crowdfense pays up to $9 million. That page has not existed since March 2025. Between the snapshots of 15 and 30 March 2025, Crowdfense cut its headline ceiling from $9,000,000 to $7,000,000, deleted its two highest tiers entirely (SMS/MMS full-chain zero-click at $7M to $9M, and Mobile App at $5M), halved virtualisation from $1,000,000 to $500,000, and dropped desktop from $2,000,000 to $1,500,000 multi. The list has not moved in the sixteen months since, while the company kept publishing research through June 2026. The freeze is a choice, not neglect.

The full picture from the primary sources org's own:

The control result
Published offensive prices are flat to down, and the market's price-signalling infrastructure is decaying. No broker raised a price in 2026, none added an AI category, and none has published any policy on AI-generated submissions.

Note carefully what this does not say. Crowdfense's cut lands in March 2025, roughly a year before the defensive repricing wave, and carries no AI rationale at all. Reading it as an AI effect would be exactly the error this edition is trying to avoid. What the control establishes is narrower and more useful: across the sixteen months in which the defensive market repriced loudly and repeatedly blamed AI, the market that buys finished chains did not respond to AI in any observable way.

Two readings survive, and both are interesting. Either AI has not changed what it costs to produce a chain against a hardened target, which is what the benchmark evidence in Section 3 says. Or offensive prices were never set by discovery cost at all, and are set instead by buyer demand, scarcity, and the willingness of a small number of sovereign customers to pay. The evidence supports the second reading more than most people expect.

What the offense side says about AI when it speaks for itself

Two first-party datapoints, both from 2026, both pointing the same way as Section 3.

Crowdfense researchers, June 2026
A broker's own researchers, on using a commercial model in their n-day work: it is “very good at the repetitive, mechanical parts of the job” and “a genuine force multiplier”, but “the bugs here did not come from the model deciding on its own what mattered; they came from steering itsingle.
Google Threat Intelligence, May 2026
The first LLM-assisted zero-day observed in the wild was a two-factor bypass logic flaw in an open-source admin tool, not a memory-corruption chain. Analysts inferred AI authorship from a hallucinated CVSS score and tutorial-style docstrings left in the exploit thin.

When AI finally turned up in a real attack, it turned up at the logic-flaw tier in open-source software: precisely the tier the defensive market has been cutting, and nowhere near the memory-corruption mobile chains that command five to seven million dollars. The offense side and the defence side are describing the same capability boundary from opposite sides of it.

What a court record adds that no price list can

The Williams prosecution, sentenced February 2026 org's own, is the rare case where the inside of a transaction is visible, and it complicates every published figure on this page. He was contracted for $4,000,000 across seven components after an initial sale at $240,000, and realised $1,300,000. Contracted price and realised payment diverge roughly threefold, so a single price-per-exploit number is a category error. The record also confirms that the deals involved “additional periodic payments for follow-on support”: exploit sales are subscriptions with maintenance, which this paper's maintenance force has always assumed and could not previously cite from a court document.

And the sharpest number in either corpus: $35,000,000 of admitted loss across eight components implies roughly $4,400,000 to develop each one at a top-tier Western contractor, against $162,500 realised on distressed grey-market resale. A 27-fold gap between what it costs to build a chain and what a cornered seller gets for one. If AI were collapsing chain production costs, that build-side number is where it would show up first.

There is a third piece of evidence hiding in Apple's October 2025 announcement. Apple raised its top award to $2,000,000 and, across the entire post, never mentions AI once. Its stated reason is mercenary spyware:

“the most advanced adversaries will continue to evolve their techniques. As a result, we're adapting Apple Security Bounty to encourage highly advanced research on our most critical attack surfaces despite the increased difficulty”

The largest defensive raise of the period is priced against the offensive market's bid, not against discovery economics. The defensive ceiling is downstream of the offensive one. That is the oldest claim in this paper and it just got a first-party confirmation from the vendor with the most to lose by saying it.

Section 6The fifth object nobody will price

While the four existing objects were being resorted, a fifth appeared: the vulnerability that exists only because a model is in the loop. The striking thing is not what it costs. It is that almost nobody will name a price at all.

Read the exclusions rather than the headlines:

What the exclusions are saying
The market prices AI vulnerabilities as a delivery mechanism for old bugs, not as a new class of asset. Money follows confidentiality and integrity compromise reached through the model. Misbehaving text is worth little, and unbounded misbehaving text is worth nothing.

The economics are legible once stated. A defect you cannot fully close, that recurs in unbounded variations, and that produces no durable capability is uninsurable: paying per instance means paying forever for something you cannot retire. So the classes that cannot be closed get moved out of the price system entirely, into venues that pay for deterrence rather than remediation. Anthropic pays up to $35,000 for a novel universal jailbreak, invite-only. OpenAI pays $50,000 for one specific biosafety universal jailbreak. Those are not defect prices. They are prices for an existence proof.

Two details make the point sharper. First, the classes the model owners refuse to price are picked up by third parties: Mozilla's 0DIN pays up to $15,000 for jailbreaks and prompt injection across models it does not own, and the single largest purse in AI security research, roughly $171,800, was funded by a government AI safety institute rather than by any vendor. When the party bearing the risk will not pay and an outside party will, the market is disagreeing with itself about who the vulnerability belongs to.

Second, and most telling for a paper about the offensive market: CVE-2025-32711, a zero-click prompt-injection data exfiltration in Microsoft 365 Copilot, was real, remotely triggered, assigned a CVE and patched. No exploit broker assigns a standing price to that class. An AI-native vulnerability can be entirely real and still be worth nothing to the buyers who pay the most for capability, because it is patchable by a prompt change, non-persistent and unreliable. It fails every property that makes an exploit an asset.

Section 7Six rival explanations, at full strength

The sorting account above is not the only story that fits these facts, and several of the alternatives are strong. Presenting them weakly would be a way of not testing the argument, so here they are at their best.

Rival 1
It is budget, and AI is the acceptable reason.

Bounty spend is discretionary operating expense. In a flat-budget year, “AI slop forced our hand” is a far more comfortable line than “we cut a line item”. This is close to unfalsifiable from outside the organisation, which is exactly why it deserves top billing rather than a footnote. The strongest supporting datapoint is not even an AI story: Immunefi's average critical payout fell about 45 percent in 2025 thin with no AI attribution at all, over a period when the underlying asset rose. Budget cycles do independent work that AI narratives can absorb.

Rival 2
It is volume, not sorting. More valid findings at a constant budget means a lower unit price.

This one is dangerous because it is also an AI story and it explains the same evidence without needing any claim about capability tiers. Google states it directly: per-bug payouts down, aggregate expected to rise. HackerOne logged valid AI-asset reports up more than 200 percent and autonomous-agent reports validating at about 49 percent, which is roughly the historical human rate. If supply of genuinely valid findings rose and budgets did not, the price falls by pure mechanics. The sorting account and the volume account are not mutually exclusive, and the volume account needs less machinery.

Rival 3
It is duplication, not slop, and it is a rediscovery-rate story the model already prices.

Linus Torvalds described the kernel security list as “almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools” multi. Django's own account names duplicates and already-fixed issues, not fabrications. A top hunter reports a model finding roughly ten bugs overnight of which about half were duplicates. If AI raises the rediscovery rate, every exploit's expected life shortens and its price falls, and that is a mechanism this paper has priced since 2022. It requires no new theory at all.

Rival 4
The timeline does not fit. The noise arrived years before the cuts.

Seth Larson was writing about hallucinated security reports to CPython in December 2024. Daniel Stenberg published his numbers in July 2025. The wave of cuts lands in 2026. A two-year lag between a stated cause and its claimed effect needs explaining, and “budgets tightened in 2026” explains it more simply than anything in Section 4.

Rival 5
It is the incentive, not the technology. The money was making the noise.

The sharpest single piece of evidence against a pure-AI account comes from the most-cited victim of AI slop. Stenberg on why reports flooded in: “We suspect the idea of getting money for it is a big part of the explanation.” And after curl removed the bounty, he reported the inflow had “dried out substantially”. If removing the reward removes the flood, the flood was a response to the reward, and AI merely lowered the cost of answering it. Note also that curl's payouts totalled only about $100,000 over seven years: the bounty was never the expensive part, so cutting it cannot have been a cost-saving measure.

Rival 6
Gating is not new, and calling it an AI response is ahistorical.

Private and invite-only programs have been the majority of platform activity since the industry's early days. On HackerOne's own published figures, private programs were 92 percent of its bounty programs in 2016, 88 percent in 2017 and 79 percent in 2018 org's own, with roughly 80 percent cited more recently. The funnel was mostly closed before any of this, and no published 2025 or 2026 platform statistic shows the private share rising because of AI. GitHub's VIP tier is a well-documented instance of a twelve-year-old pattern, not a new invention. In the interest of full disclosure, I helped popularise that pattern; that is a reason to be careful about calling it novel, not a reason to omit it.

Where the author has already been wrong in public

In July 2025 I told TechCrunch that AI had not yet caused a significant spike in low-quality reports on Bugcrowd, and that submission quality was “not any better or worse”. Volume was up; quality, at that point, was not visibly down. A year later the picture is different in some places and still looks like that in others, and the programs that held steady are as informative as the ones that cut. Anyone using this edition should weight that 2025 statement as a prior that the 2026 evidence has partially, but not wholly, overturned.

Section 8What would falsify this

A claim that cannot be killed is not worth making. Here is what would kill this one.

The last one is worth watching closely. GitHub changed one variable, on a known date, on a program with a published before and after. If the intervention does not move signal, the stated rationale across this entire period gets substantially weaker.

Section 9How to read the evidence, and what is thin

This edition ships two machine-readable files. Neither is a clean sample, and the difference between them matters.

The corpus, and its selection bias

bounty-repricing-2026.json holds 33 rows of program price and access changes, each with an evidence tier, a source URL and, where the organisation stated one, a verbatim reason. It is assembled from announcements and press, so it inherits an obvious bias: a program raising its payouts is rarely news, while a program cutting them reliably is. Counting rows in that file cannot tell you the direction of the market, and the file says so in its own metadata.

The universe sample, and what it could not resolve

To get at direction, bounty-universe-sample.json takes a different approach: a fixed list of 28 programs declared before any result was seen, each of which publishes a numeric reward table, compared against its own archived page from the start of 2026. Of the 28, only 8 resolved. Most reward tables are rendered by JavaScript, or are absent from the archive, and a fetch that returns nothing is a fact about the method rather than a fact about the program. Among the rows that did resolve, seven were unchanged and one moved, and the one that moved is within the noise of the extraction method.

The most useful thing the sampler found was its own failure

GitHub's page reads $30,000 as its maximum both before and after the restructure. By the measure “highest number on the page”, nothing happened on 27 July 2026. But the public ceiling fell from roughly $30,000 to $10,000 and the old ceiling moved behind an invitation. The headline price did not move; the population who can reach it did. Any analysis that tracks published maxima will miss this entire event, which is a decent argument that published maxima are the wrong instrument and that access terms deserve to be a first-class field in vulnerability price data.

Known gaps

One more piece of counter-evidence deserves its own line, because it is the cleanest disconfirmation available. Facing the same wave, Mozilla cut nothing. It named the identical problem, that “reports that look plausibly correct but are wrong impose an asymmetric cost on project maintainers”, then built verification tooling and invited an AI lab to submit model-found issues in bulk. Same input, opposite output. Whatever the 2026 repricing is, it is not deterministic.

Section 10Sources

Every figure on this page traces to one of these. Full per-row citations, evidence tiers, archive notes and verbatim stated reasons are in the JSON corpus.

Program announcements

AI-system reward tables

Capability evidence

Platform and ecosystem data

Offensive control