{
  "version": "2026-07-28-offensive-corrected+archived-30of33",
  "source": "research/2026-07-28-ai-repricing/RESEARCH.md",
  "scope": "Defensive-side vulnerability reward program price and access changes, 2025-01-01 through 2026-07-28, plus the reward tables of programs covering AI systems themselves, plus offensive-broker control rows and offensive-market context rows added 2026-07-28. This file is the DEFENSIVE companion to confirmed-prices-2026-04.json, which remains offensive-transactions-only. The two files are deliberately not merged: rows here are mostly PUBLISHED OFFERS (reward tables), while rows there are CONFIRMED TRANSACTIONS. Merging them would silently mix evidence classes.",
  "sampling_warning": "This file is assembled from announcements and press, so it inherits a selection bias: a program raising its payouts is rarely news, while a program cutting them reliably is. Counts drawn from this file therefore CANNOT support a claim about the direction of the market as a whole. For a direction claim, use data/bounty-universe-sample.json, which samples a fixed pre-declared universe of programs against their own archived reward pages and reports the distribution including 'no change'.",
  "schema": {
    "id": "Stable corpus row id",
    "org": "Organization operating the program",
    "program": "Program name",
    "change_type": "raise | cut | restructure | gate | suspend | terminate | new-program | context",
    "date_announced": "YYYY-MM-DD of the announcement",
    "date_effective": "YYYY-MM-DD the change took effect, if distinct",
    "market_side": "defensive | offensive-control",
    "object_class": "Which of the paper's four pricing objects this reward is really buying: defect | primitive | chain | access | ai-behaviour | mixed",
    "old_value": "Prior figure(s), or null",
    "old_value_confidence": "Confidence tier for the OLD figure specifically, which is frequently weaker than the new figure because announcements state what changes to, not what it changed from",
    "new_value": "New figure(s)",
    "value_kind": "announced-offer (a published ceiling, may never have been paid) | paid (a disclosed actual payout or total)",
    "scope_note": "What class of finding or researcher the change applies to",
    "stated_reason": "Verbatim quote of the organization's own stated reason, or null",
    "ai_attributed": "explicit (the org names AI) | implied | no (the org does not mention AI)",
    "confidence_tier": "1 (the organization's own announcement, fetched) | 2 (multi-outlet reporting) | 3 (single-outlet reporting) | 4 (third-party analysis or inference)",
    "source_url": "Primary citation URL",
    "corroborating_url": "Secondary citation URL, where the primary is JS-rendered or paywalled",
    "archive_url": "Third-party archive snapshot. null if none exists yet.",
    "archive_note": "Why archive_url is null, when it is",
    "notes": "Caveats, reconciliation, and anything that complicates the row"
  },
  "confidence_scale_note": "Tier 1 requires that the organization's own page was actually fetched during research on 2026-07-28, not recalled. Where a primary page is JS-rendered, it was rendered with headless Chrome and the extracted text is the basis for the row.",
  "rows": [
    {
      "id": "R01",
      "org": "GitHub",
      "program": "GitHub Bug Bounty (HackerOne)",
      "change_type": "restructure",
      "date_announced": "2026-07-22",
      "date_effective": "2026-07-27",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "Low $617-$2,000 | Medium $4,000-$10,000 | High $10,000-$20,000 | Critical $20,000-$30,000+ (ranges)",
      "old_value_confidence": 2,
      "new_value": "PUBLIC (fixed): Low $250 | Medium $2,000 | High $5,000 | Critical $10,000. VIP (invite-only): Low $1,000 | Medium $7,500 | High $20,000 | Critical $30,000+",
      "value_kind": "announced-offer",
      "scope_note": "Whole program. VIP invitation threshold: one accepted critical, or two high, or four medium, or seven low. New HackerOne Signal requirement gates the public program; researchers without signal are limited to a small number of initial submissions. Reports submitted before the effective date, including triage backlog, honoured at old rates.",
      "stated_reason": "To reduce the volume of low-effort and AI-generated reports, we're implementing a HackerOne signal requirement",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/",
      "corroborating_url": "https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html",
      "archive_url": "http://web.archive.org/web/20260727151404/https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/",
      "notes": "GitHub's own post states the NEW tables and the effective date but does NOT restate the previous amounts, so old_value is press-derived at tier 2 and should not be cited as GitHub's own figure. Also quoted from the post: 'The core shift here is in what we're incentivizing: you don't earn more by submitting more. You earn more by submitting better.' Note the top of the range did not move: $30,000+ was the prior critical ceiling and remains the VIP critical ceiling. What changed is who can reach it."
    },
    {
      "id": "R02",
      "org": "Google",
      "program": "Chrome Vulnerability Reward Program",
      "change_type": "cut",
      "date_announced": "2026-04-30",
      "date_effective": "2026-04-30",
      "market_side": "defensive",
      "object_class": "primitive",
      "old_value": "Enhanced bonuses for renderer RCE and arbitrary read/write, introduced 2025",
      "old_value_confidence": 2,
      "new_value": "Renderer RCE and arbitrary R/W special bonuses retired. Full-chain browser-process exploit reward retained at up to $250,000; MiraclePtr bypass bonus retained at up to $250,128.",
      "value_kind": "announced-offer",
      "scope_note": "Shallow and mid-tier memory-safety demonstration classes cut; full-chain rewards held.",
      "stated_reason": "Today, AI has made demonstrating these techniques almost routine, allowing us to focus on more complex, novel escalation methods. As a result, we are retiring these specific special bonuses.",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era",
      "corroborating_url": "https://www.securityweek.com/google-adjusts-bug-bounties-chrome-payouts-drop-as-android-rewards-rise-amid-ai-surge/",
      "archive_url": "http://web.archive.org/web/20260618042642/https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era",
      "notes": "This is the single most important row in the file. Google names the mechanism directly: the bonus was retired because AI made that specific demonstration routine. The cut is class-specific, not program-wide, and lands precisely on the capability tier where AI is measurably competent."
    },
    {
      "id": "R03",
      "org": "Google",
      "program": "Android and Google Devices Vulnerability Reward Program",
      "change_type": "raise",
      "date_announced": "2026-04-30",
      "date_effective": "2026-04-30",
      "market_side": "defensive",
      "object_class": "chain",
      "old_value": "$1,000,000 zero-click full chain Pixel Titan M2 with persistence; $750,000 tier did not previously exist at this level",
      "old_value_confidence": 2,
      "new_value": "Up to $1,500,000 for a zero-click full chain Pixel Titan M2 compromise with persistence; up to $750,000 for a zero-click full chain Pixel Titan M2 compromise",
      "value_kind": "announced-offer",
      "scope_note": "Top-tier hardened-target chains only. Linux kernel reports narrowed to Google-maintained components absent concrete proof of exploitability on Android.",
      "stated_reason": "We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents.",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era",
      "corroborating_url": "https://www.bleepingcomputer.com/news/security/google-now-offers-up-to-15-million-for-some-android-exploits/",
      "archive_url": "http://web.archive.org/web/20260618042642/https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era",
      "notes": "Published in the SAME post as the Chrome cut (R02), by the same authors, on the same day. One announcement contains a cut and a raise, and states an AI-capability rationale for both. This is the cleanest available evidence that the 2026 repricing is a sorting operation along the line of what AI can and cannot do, rather than a general retreat. Announced maximum only: Google's highest single reward actually paid in 2025 was $250,000."
    },
    {
      "id": "R04",
      "org": "Google",
      "program": "All Google VRPs",
      "change_type": "context",
      "date_announced": "2026-03-11",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "approximately $12M paid in 2024",
      "old_value_confidence": 2,
      "new_value": "$17,100,000 paid in 2025 to 747 researchers; highest single reward $250,000; $81,600,000 cumulative since 2010",
      "value_kind": "paid",
      "scope_note": "Actually-paid totals across all Google reward programs, the counterweight to every announced-ceiling row in this file.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://blog.google/security/vrp-2025-year-in-review/",
      "corroborating_url": "https://www.bleepingcomputer.com/news/google/google-paid-171-million-for-vulnerability-reports-in-2025/",
      "archive_url": "http://web.archive.org/web/20260726213619/https://blog.google/security/vrp-2025-year-in-review/",
      "notes": "Google's 2025 total was an all-time high, up more than 40% on 2024, in the same period it was cutting per-bug amounts. In the April 2026 announcement Google states directly: 'While these adjustments may reduce the payout for a single bug report, we continue to prioritize our VRPs and the total aggregate rewards paid out in 2026 is expected to increase.' Unit price down, aggregate up. Any account of 2026 that describes the defensive market as simply retreating has to explain this row."
    },
    {
      "id": "R05",
      "org": "Google",
      "program": "Open Source Software VRP",
      "change_type": "gate",
      "date_announced": "2026-03-19",
      "date_effective": "2026-03-19",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Rule updates; no payout change identified",
      "value_kind": "announced-offer",
      "scope_note": "Intake quality gating rather than price change.",
      "stated_reason": "updates to the OSS VRP rules which are designed to help us filter out low-quality reports and focus on real-world impact",
      "ai_attributed": "implied",
      "confidence_tier": 1,
      "source_url": "https://bughunters.google.com/feed/en",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260409081409/https://bughunters.google.com/feed/en",
      "notes": "Included because gating without a price change is a distinct and common response, and counting it as a cut would overstate the price story."
    },
    {
      "id": "R06",
      "org": "Apple",
      "program": "Apple Security Bounty",
      "change_type": "raise",
      "date_announced": "2025-10-10",
      "date_effective": "2025-11",
      "market_side": "defensive",
      "object_class": "chain",
      "old_value": "$1,000,000 maximum for a zero-click remote chain with no user interaction",
      "old_value_confidence": 1,
      "new_value": "$2,000,000 for exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks; maximum payout in excess of $5,000,000 with Lockdown Mode and beta-software bonuses",
      "value_kind": "announced-offer",
      "scope_note": "Top-tier chains across all Apple platforms. Also raised: one-click and wireless-proximity chains to $1,000,000, physical access and app sandbox escape to $500,000. Target Flags introduced for objectively demonstrable exploitability and accelerated payment.",
      "stated_reason": "the most advanced adversaries will continue to evolve their techniques. As a result, we're adapting Apple Security Bounty to encourage highly advanced research on our most critical attack surfaces despite the increased difficulty",
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://security.apple.com/blog/apple-security-bounty-evolved/",
      "corroborating_url": "https://9to5mac.com/2025/10/10/apple-announces-major-evolution-of-its-security-bounty-program-2-million-top-award-more/",
      "archive_url": "http://web.archive.org/web/20260713030616/https://security.apple.com/blog/apple-security-bounty-evolved/",
      "notes": "The largest raise in the period, and AI is never mentioned in the announcement. Apple prices explicitly against mercenary spyware capability, which means this defensive ceiling is set by the offensive market's bid rather than by discovery economics. Apple states it has paid more than $35,000,000 to over 800 researchers since 2020. Announced maximum: Apple notes no successful Gatekeeper or broad iCloud exploit has ever been demonstrated."
    },
    {
      "id": "R07",
      "org": "curl",
      "program": "curl bug bounty (via Internet Bug Bounty on HackerOne)",
      "change_type": "terminate",
      "date_announced": "2026-01-26",
      "date_effective": "2026-01-31",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": "Paid bounties; more than $100,000 across 87 confirmed vulnerabilities since April 2019",
      "old_value_confidence": 1,
      "new_value": "$0. Reports via GitHub private vulnerability reporting or security@curl.se, no monetary rewards offered.",
      "value_kind": "announced-offer",
      "scope_note": "Entire project. Program ended, disclosure channel retained.",
      "stated_reason": "an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/",
      "corroborating_url": "https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/",
      "archive_url": "http://web.archive.org/web/20260727034024/https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/",
      "notes": "The most fully documented case in the file because the maintainer published his own accounting: confirmed-vulnerability rate fell from north of 15% to below 5% during 2025, roughly 20% of 2025 submissions were AI slop, and each report consumed three to four of seven security team members for between thirty minutes and three hours. Stenberg also names money itself as part of the cause: 'We suspect the idea of getting money for it is a big part of the explanation.' Note the timeline problem this row creates for any simple AI story: Stenberg was publishing about slop in 2025, and Seth Larson at the Python Software Foundation in December 2024, well before the 2026 wave of cuts."
    },
    {
      "id": "R08",
      "org": "Nextcloud",
      "program": "Nextcloud bug bounty (HackerOne)",
      "change_type": "suspend",
      "date_announced": "2026-04-22",
      "date_effective": "2026-04-22",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": "Rewards up to $10,000",
      "old_value_confidence": 3,
      "new_value": "$0. Program continues unpaid; valid reports still fixed and credited; reporters must show manual verification with screenshots.",
      "value_kind": "announced-offer",
      "scope_note": "Entire program.",
      "stated_reason": "a high number of AI-generated illegitimate reports",
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://hackerone.com/nextcloud",
      "corroborating_url": "https://www.heise.de/en/news/Due-to-AI-Bug-bounty-programs-without-rewards-now-also-at-Nextcloud-11271443.html",
      "archive_url": "http://web.archive.org/web/20260723141931/https://hackerone.com/nextcloud",
      "notes": "The prior $10,000 ceiling and the reported twenty-to-thirty-fold increase in triage time per report are secondary-sourced and should be cited as such."
    },
    {
      "id": "R09",
      "org": "HackerOne",
      "program": "Internet Bug Bounty",
      "change_type": "suspend",
      "date_announced": "2026-03-27",
      "date_effective": "2026-03-27",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": "Open for submissions",
      "old_value_confidence": 2,
      "new_value": "Submissions paused",
      "value_kind": "announced-offer",
      "scope_note": "Bounties for maintainer-confirmed CVEs in core open-source projects. Lifetime more than $1,500,000 awarded, 80% to finder and 20% to maintainers.",
      "stated_reason": "AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted.",
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://hackerone.com/ibb",
      "corroborating_url": "https://www.infoworld.com/article/4154210/internet-bug-bounty-program-hits-pause-on-payouts.html",
      "archive_url": "http://web.archive.org/web/20260704052920/https://hackerone.com/ibb",
      "notes": "The stated reason is unusually precise and does not claim slop. It claims a capacity mismatch: discovery outran remediation. That is a different economic argument from the triage-cost one, and it is the argument most consistent with the capability evidence."
    },
    {
      "id": "R10",
      "org": "HackerOne",
      "program": "Internet Bug Bounty",
      "change_type": "cut",
      "date_announced": "2026-05-18",
      "date_effective": "2026-05-18",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": "Critical $9,250 | High $4,429 | Medium $1,843 | Low $597",
      "old_value_confidence": 3,
      "new_value": "Critical $2,257 | High $1,009 | Medium $297 | Low $68",
      "value_kind": "announced-offer",
      "scope_note": "IBB reward table, while submissions remained paused.",
      "stated_reason": "The Internet Bug Bounty is a unique, dynamic program where bounty levels automatically adjust based on the contributions from active participating sponsors. Payouts under this program are regularly adjusted accordingly.",
      "ai_attributed": "no",
      "confidence_tier": 3,
      "source_url": "https://www.theregister.com/security/2026/05/21/hackerone_takes_an_axe_to_its_bug_bounty_rewards/",
      "corroborating_url": null,
      "archive_url": null,
      "archive_note": "Single-outlet original observation of the live bounty table; the table itself is JS-rendered and could not be independently re-read.",
      "notes": "A 76% to 89% cut across all severities. Important for honesty: HackerOne explicitly did NOT attribute this cut to AI, attributing it instead to sponsor funding mechanics, weeks after attributing the submissions pause to AI. Anyone building an AI-causes-cuts narrative has to account for the fact that the largest percentage cut in this file is the one its operator declined to blame on AI."
    },
    {
      "id": "R11",
      "org": "Bugcrowd",
      "program": "Platform-wide submission policy",
      "change_type": "gate",
      "date_announced": "2026-03-10",
      "date_effective": "2026-03-10",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "No identity verification or submission throttling requirement",
      "old_value_confidence": 2,
      "new_value": "Permanent bans for submission farming; 30-day suspension at ten or more consecutive invalid reports; identity verification after ten or more cumulative invalid reports",
      "value_kind": "announced-offer",
      "scope_note": "Intake pipeline only. NO reward-amount change.",
      "stated_reason": "Over the past three weeks alone, our queues have increased by more than 334%",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.bugcrowd.com/blog/bugcrowd-policy-changes-to-address-ai-slop-submissions/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260720120821/https://www.bugcrowd.com/blog/bugcrowd-policy-changes-to-address-ai-slop-submissions/",
      "notes": "Recorded precisely because it is frequently miscounted. Bugcrowd is a platform, not a program, and no evidence was found that Bugcrowd cut or restructured any reward amount in 2025 or 2026. Its response was entirely intake gating plus positive incentives for high-signal researchers. Press describing 2026 as four programs restructuring should not be read as four programs cutting prices."
    },
    {
      "id": "R12",
      "org": "Bugcrowd",
      "program": "Platform-wide submission policy",
      "change_type": "gate",
      "date_announced": "2026-05-18",
      "date_effective": "2026-05",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "Identity verification only after repeated invalid reports",
      "old_value_confidence": 1,
      "new_value": "Mandatory identity verification for ALL researchers, new and existing, before any Managed Bug Bounty submission; submission throttling on low-performance accounts; CAPTCHA before submission across all engagement types. VDPs exempt.",
      "value_kind": "announced-offer",
      "scope_note": "Platform-wide intake. Still no reward-amount change.",
      "stated_reason": "submission volumes have increased materially, with a disproportionate share driven by speculative or AI-generated reports submitted with minimal to no pre-submission validation",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.bugcrowd.com/blog/continuing-our-work-to-reduce-ai-slop-submissions-and-protect-signal-quality/",
      "corroborating_url": "https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity/",
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "Mandatory identity verification is the purest example in the file of a program paying to establish who is on the other end rather than changing what it pays for a finding. The cost being managed is attribution, not reward."
    },
    {
      "id": "R13",
      "org": "Django Software Foundation",
      "program": "Security reporting policy (no bounty)",
      "change_type": "gate",
      "date_announced": "2026-02-04",
      "date_effective": "2026-02-04",
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "AI-assisted reports must disclose which tools were used and for what; reporter must verify a real reproducible vulnerability; fabricated code, placeholder text, and non-existent features rejected",
      "value_kind": "announced-offer",
      "scope_note": "Django pays no bounties; this is a pure intake-quality change.",
      "stated_reason": "on a nearly daily basis we get reports duplicating other pending reports, or even reports about vulnerabilities that have already been fixed... Clearly, reporters are using LLMs to generate (initially) plausible variations.",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.djangoproject.com/weblog/2026/feb/04/recent-trends-security-team/",
      "corroborating_url": "https://socket.dev/blog/django-joins-curl-in-pushing-back-on-ai-slop-security-reports",
      "archive_url": "http://web.archive.org/web/20260513215841/https://www.djangoproject.com/weblog/2026/feb/04/recent-trends-security-team/",
      "notes": "The named problem is DUPLICATION, not fabrication: many people running the same tools against the same code produce the same findings. That is a rediscovery-rate story, which the interactive model already prices, rather than a fraud story."
    },
    {
      "id": "R14",
      "org": "GitLab",
      "program": "GitLab bug bounty",
      "change_type": "gate",
      "date_announced": "2026-01-20",
      "date_effective": "2026-01-22",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "Denial of service in scope; standalone prompt injection eligible",
      "old_value_confidence": 2,
      "new_value": "Denial of service out of scope except unauthenticated persistent total disruption; standalone prompt injection out of scope, eligible only as an initial vector for broader harm. Payouts unchanged.",
      "value_kind": "announced-offer",
      "scope_note": "Scope narrowing without a price change.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://about.gitlab.com/blog/gitlab-bug-bounty-program-policy-updates/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260707052126/https://about.gitlab.com/blog/gitlab-bug-bounty-program-policy-updates/",
      "notes": "An AI-adjacent scope change with no AI rationale given. Notable as one of several programs to declare standalone prompt injection unpriced."
    },
    {
      "id": "R15",
      "org": "Microsoft",
      "program": "Zero Day Quest",
      "change_type": "raise",
      "date_announced": "2025-08-05",
      "date_effective": "2026-04",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "$4,000,000 prize pool (2025 event); $1,600,000 actually awarded",
      "old_value_confidence": 1,
      "new_value": "$5,000,000 prize pool (2026 event); $2,300,000 actually awarded across 80+ cloud and AI vulnerabilities",
      "value_kind": "paid",
      "scope_note": "Cloud and AI research event. Copilot bounty carries a 100% award multiplier.",
      "stated_reason": "prioritizing the highest-impact security scenarios for Copilot and Cloud",
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.microsoft.com/en-us/msrc/blog/2026/04/zero-day-quest-2026-over-2-million-awarded-vulnerability-research",
      "corroborating_url": "https://www.microsoft.com/en-us/msrc/blog/2025/08/microsoft-bounty-program-year-in-review-17-million-in-rewards",
      "archive_url": "http://web.archive.org/web/20260724204448/https://www.microsoft.com/en-us/msrc/blog/2026/04/zero-day-quest-2026-over-2-million-awarded-vulnerability-research",
      "notes": "Microsoft invokes AI only as attack surface to invest in, never as a report-flood problem to defend against. It paid $17,000,000 across all programs in FY2025 to 344 researchers, a record. A vendor with the budget to absorb triage cost raised."
    },
    {
      "id": "R16",
      "org": "Mozilla",
      "program": "Firefox client bug bounty",
      "change_type": "context",
      "date_announced": "2026-05-07",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "primitive",
      "old_value": "Unchanged",
      "old_value_confidence": 2,
      "new_value": "No payout change. Mozilla built verification harnesses and invited an AI lab to submit model-discovered findings in bulk.",
      "value_kind": "announced-offer",
      "scope_note": "The clearest disconfirming case in the file.",
      "stated_reason": "Dealing with reports that look plausibly correct but are wrong imposes an asymmetric cost on project maintainers",
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/",
      "corroborating_url": "https://www.scworld.com/news/mozilla-fixes-22-firefox-vulnerabilities-discovered-by-anthropics-claude-ai",
      "archive_url": "http://web.archive.org/web/20260721105258/https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/",
      "notes": "Mozilla identified exactly the same asymmetric-cost problem as curl and GitHub and responded by investing in verification rather than cutting price. This row is why the triage-cost mechanism cannot be treated as deterministic: the same input produced the opposite output at an organisation that chose to absorb it."
    },
    {
      "id": "R17",
      "org": "Immunefi",
      "program": "Web3 bounty platform (aggregate)",
      "change_type": "cut",
      "date_announced": "2025-12",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "Average critical payout $46,228 (2024)",
      "old_value_confidence": 4,
      "new_value": "Average critical payout $25,617 (2025), down approximately 45%; total dollar payouts down approximately 41% year on year",
      "value_kind": "paid",
      "scope_note": "Averages across Immunefi-hosted programs. Posted theoretical maxima unchanged.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 4,
      "source_url": "https://coinlaw.io/smart-contract-bug-bounties-statistics/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260130045548/https://coinlaw.io/smart-contract-bug-bounties-statistics/",
      "notes": "Carried deliberately as a control. A 41-45% decline in actually-paid amounts in an adjacent bounty market with no AI attribution at all, over a period when the underlying asset rose. Budget cycles and market conditions do independent work that AI narratives can absorb. Weakest confidence tier in the file; do not cite as a headline."
    },
    {
      "id": "R18",
      "org": "HackerOne",
      "program": "Platform (9th Hacker-Powered Security Report)",
      "change_type": "context",
      "date_announced": "2025-10",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "$81,000,000 bounties paid in the report year, up 13%; 85,000 total valid reports, up 7%; valid AI-asset vulnerability reports up more than 200% year on year; prompt-injection findings up 540%; 1,121 customer programs with AI in scope, up 270%; 560+ valid reports from fully autonomous agents; 49% of hackbot reports validated; 70% of researchers use AI tools",
      "value_kind": "paid",
      "scope_note": "Platform-wide statistics.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.hackerone.com/press-release/hackerone-report-finds-210-spike-ai-vulnerability-reports-amid-rise-ai-autonomy",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260426125414/https://www.hackerone.com/press-release/hackerone-report-finds-210-spike-ai-vulnerability-reports-amid-rise-ai-autonomy",
      "notes": "The most important counterweight to the slop narrative, and it comes from the platform with the most to gain from an AI story in either direction. A 49% validation rate on autonomous-agent reports is not slop; it is roughly the historical human valid rate. Total valid reports and total payouts both ROSE. Platform annual reports are marketing documents as well as data, and HackerOne also sells the triage-automation product that solves the problem it documents."
    },
    {
      "id": "R19",
      "org": "OpenAI",
      "program": "Bug Bounty Program (Bugcrowd)",
      "change_type": "raise",
      "date_announced": "2025-03-28",
      "date_effective": "2025-03-28",
      "market_side": "defensive",
      "object_class": "mixed",
      "old_value": "$20,000 maximum",
      "old_value_confidence": 2,
      "new_value": "$100,000 maximum for exceptional and differentiated critical findings",
      "value_kind": "announced-offer",
      "scope_note": "Traditional infrastructure and product security vulnerabilities. Model safety issues, jailbreaks, and safety bypasses are explicitly excluded from this program.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 2,
      "source_url": "https://openai.com/index/bug-bounty-program/",
      "corroborating_url": "https://www.bleepingcomputer.com/news/security/openai-now-pays-researchers-100-000-for-critical-vulnerabilities/",
      "archive_url": "http://web.archive.org/web/20260708122740/https://openai.com/index/bug-bounty-program/",
      "notes": "The exclusion is the economically informative part: an AI company's security bounty pays for classical infrastructure bugs and explicitly refuses to pay for model behaviour."
    },
    {
      "id": "R20",
      "org": "OpenAI",
      "program": "Safety Bug Bounty (Bugcrowd)",
      "change_type": "new-program",
      "date_announced": "2026-03-25",
      "date_effective": "2026-03-25",
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Reported maximum $100,000 for critical findings. UNVERIFIED against OpenAI's own page.",
      "value_kind": "announced-offer",
      "scope_note": "Third-party prompt injection that reliably hijacks a victim's agent, agent data exfiltration, disallowed autonomous actions at scale, anti-automation bypass, Model Context Protocol risks. Must reproduce at least 50% of the time. Jailbreaks explicitly out of scope.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 3,
      "source_url": "https://openai.com/index/safety-bug-bounty/",
      "corroborating_url": "https://www.helpnetsecurity.com/2026/03/27/openai-safety-bug-bounty-program/",
      "archive_url": "http://web.archive.org/web/20260702025011/https://openai.com/index/safety-bug-bounty/",
      "notes": "The maximum figure is reported rather than confirmed and secondary coverage appears to conflate it with the separate security bounty ceiling. Treated as tier 3 and should be presented with that hedge. The scope itself is well-sourced: note that prompt injection becomes payable only when it produces a concrete downstream harm, and jailbreaks remain unpriced."
    },
    {
      "id": "R21",
      "org": "Anthropic",
      "program": "Model Safety Bug Bounty (HackerOne, invite-only)",
      "change_type": "raise",
      "date_announced": "2026-03-16",
      "date_effective": "2026-03-16",
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": "$15,000 maximum at launch, 2024-08-08",
      "old_value_confidence": 1,
      "new_value": "Up to $35,000 per novel universal jailbreak",
      "value_kind": "announced-offer",
      "scope_note": "Novel UNIVERSAL jailbreaks only, tested against unreleased mitigations, focused on chemical, biological, radiological, nuclear and cyber domains. Narrow or single-domain jailbreaks excluded. Ordinary infrastructure vulnerabilities route to a separate policy.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
      "corroborating_url": "https://www.anthropic.com/news/model-safety-bug-bounty",
      "archive_url": "http://web.archive.org/web/20260712222535/https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
      "notes": "Invite-only from launch. The pricing is deterrence pricing: the program pays for the existence proof of a class of failure, not for a defect to be remediated."
    },
    {
      "id": "R22",
      "org": "OpenAI",
      "program": "Bio Bug Bounty",
      "change_type": "raise",
      "date_announced": "2026-07-09",
      "date_effective": "2026-07-09",
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": "$25,000 universal jailbreak of the biosafety challenge",
      "old_value_confidence": 3,
      "new_value": "$50,000; program made ongoing and private",
      "value_kind": "announced-offer",
      "scope_note": "A single universal jailbreak defeating a predefined biosafety challenge across frontier models. Narrow single-question jailbreaks excluded.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 3,
      "source_url": "https://openai.com/index/bio-bug-bounty/",
      "corroborating_url": "https://www.techrepublic.com/article/news-openai-bio-bounty-jailbreak/",
      "archive_url": "http://web.archive.org/web/20260716121059/https://openai.com/index/bio-bug-bounty/"
    },
    {
      "id": "R23",
      "org": "Google",
      "program": "AI Vulnerability Reward Program",
      "change_type": "new-program",
      "date_announced": "2025-10-06",
      "date_effective": "2025-10-06",
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": "Handled within the Abuse VRP",
      "old_value_confidence": 2,
      "new_value": "Top base reward $20,000 for rogue actions in flagship AI products, up to approximately $30,000 with report-quality multipliers; $15,000 standard tier; data exfiltration up to $15,000 flagship and $10,000 other",
      "value_kind": "announced-offer",
      "scope_note": "Security CONSEQUENCES of AI misuse: rogue actions, data exfiltration, phishing enablement, model theft. Prompt injection, jailbreaks, and alignment issues are explicitly OUT of scope and routed to in-product feedback.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules",
      "corroborating_url": "https://www.bleepingcomputer.com/news/google/googles-new-ai-bug-bounty-program-pays-up-to-30-000-for-flaws/",
      "archive_url": "http://web.archive.org/web/20260719175944/https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules",
      "notes": "Google states its programs have paid more than $430,000 for AI issues since 2023. The exclusions matter more than the inclusions: the largest AI company in the world declines to price prompt injection or jailbreaks at all."
    },
    {
      "id": "R24",
      "org": "Microsoft",
      "program": "Copilot AI Bounty",
      "change_type": "context",
      "date_announced": "2026-04-07",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Range $250 to $30,000. Deserialization of untrusted data (critical) $30,000; code injection (critical) $30,000; authentication issues (critical) $20,000; cross-site scripting (critical) $8,000; inference manipulation (critical) $8,000",
      "value_kind": "announced-offer",
      "scope_note": "Copilot across web, Edge, Windows, mobile and messaging surfaces, graded via Microsoft's Vulnerability Severity Classification for AI Systems.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://www.microsoft.com/en-us/msrc/bounty-ai",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260719142210/https://www.microsoft.com/en-us/msrc/bounty-ai",
      "notes": "The single most legible price comparison in the file. Within one program and one severity band, a classical code-injection bug is worth $30,000 and an AI-native inference-manipulation bug is worth $8,000. Also excluded: prompt injection with no security impact on anyone other than the attacker, and model hallucination."
    },
    {
      "id": "R25",
      "org": "Meta",
      "program": "Meta Bug Bounty, GenAI payout guidelines",
      "change_type": "context",
      "date_announced": "2024",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Access private user content up to $130,000; access sensitive internal Meta data including model weights up to $30,000; trigger privileged actions or modify sensitive data up to $20,000; prompt smuggling up to $5,000",
      "value_kind": "announced-offer",
      "scope_note": "AI products and services. Standalone prompt injection and jailbreaks not chained to an eligible risk are excluded, as are hallucinations.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 1,
      "source_url": "https://bugbounty.meta.com/payout-guidelines/meta-genai/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260630182120/https://bugbounty.meta.com/payout-guidelines/meta-genai/",
      "notes": "A 26 to 1 ratio inside one program between classical account takeover through an AI surface and the most AI-native class Meta will pay for at all. Meta paid $4,000,000 across all bounties in 2025 and approximately $25,000,000 lifetime."
    },
    {
      "id": "R26",
      "org": "Protect AI",
      "program": "huntr",
      "change_type": "context",
      "date_announced": "2023-08-08",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "defect",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Up to $50,000",
      "value_kind": "announced-offer",
      "scope_note": "AI and machine-learning SOFTWARE SUPPLY CHAIN: framework vulnerabilities, malicious model-file deserialization, ML tooling. Explicitly not model behaviour.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://huntr.com/guidelines",
      "corroborating_url": null,
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "Described as an AI bounty platform, but what it actually prices is classical code vulnerabilities in AI-adjacent software. Another instance of the pattern: the money follows the old object class."
    },
    {
      "id": "R27",
      "org": "Mozilla",
      "program": "0DIN",
      "change_type": "context",
      "date_announced": "2024",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Up to $15,000",
      "value_kind": "announced-offer",
      "scope_note": "Guardrail jailbreaks, prompt injection, interpreter jailbreak, across third-party models rather than Mozilla's own.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://0din.ai/about",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260715145856/https://0din.ai/about",
      "notes": "0DIN pays for precisely the classes the model owners themselves refuse to price. When the party bearing the risk will not pay and a third party will, the market is disagreeing with itself about who the vulnerability belongs to."
    },
    {
      "id": "R28",
      "org": "Gray Swan AI",
      "program": "Arena competitions (prize pools, not standing bounties)",
      "change_type": "context",
      "date_announced": "2025-2026",
      "date_effective": null,
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Prize pools: Harmful AI Assistant $40,000 (Jan 2025); Visual Vulnerabilities $60,000 (Mar-Apr 2025); Dangerous Reasoning $20,000 (May 2025); UK AI Security Institute Agent Red-Teaming $171,800 (Mar-Apr 2025); Machine-in-the-Middle $100,000 (Nov-Dec 2025); Safeguards Challenge $140,000 (Feb-May 2026)",
      "value_kind": "announced-offer",
      "scope_note": "Jailbreaks, agent hijacking, vision-model attacks, safeguard bypass. Pools are split across ranked participants, not paid per finding.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://app.grayswan.ai/arena",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20251015145418/https://app.grayswan.ai/arena",
      "notes": "The largest single purse for AI-behaviour research in existence was funded by a government AI safety institute, not by a vendor bounty. Willingness to pay for AI safety findings is concentrated in institutions buying assurance rather than in a functioning per-bug price."
    },
    {
      "id": "R29",
      "org": "Amazon",
      "program": "Private Nova AI bug bounty",
      "change_type": "new-program",
      "date_announced": "2025-11",
      "date_effective": "2026",
      "market_side": "defensive",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "$200 to $25,000, invite-only",
      "value_kind": "announced-offer",
      "scope_note": "Nova foundation models and AI applications. Prompt injection, jailbreak, and models enabling harmful behaviour including CBRN.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://www.amazon.science/news/amazon-launches-private-ai-bug-bounty-to-strengthen-nova-models",
      "corroborating_url": "https://cyberscoop.com/amazon-bug-bounty-program-ai-nova/",
      "archive_url": "http://web.archive.org/web/20260720142817/https://www.amazon.science/news/amazon-launches-private-ai-bug-bounty-to-strengthen-nova-models",
      "notes": "Amazon's public AI bounty has paid more than $55,000 across 30-plus validated findings cumulatively. Another AI-behaviour program that is invite-only from the start."
    },
    {
      "id": "R30",
      "org": "Crowdfense",
      "program": "Exploit Acquisition Program",
      "change_type": "context",
      "date_announced": "2024",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "iOS zero-click full chain from $5,000,000 to $7,000,000; Android zero-click full chain $5,000,000; Chrome one-click full chain $2,000,000 to $3,000,000; Safari one-click full chain $2,500,000 to $3,500,000; Windows zero-click full chain $1,000,000. Program funded at $30,000,000; range $10,000 to $7,000,000. NO AI, LLM, or model category.",
      "value_kind": "announced-offer",
      "scope_note": "Offensive broker control row. List unchanged since 2025-03-30.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://www.crowdfense.com/exploit-acquisition-program/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260217085713/https://www.crowdfense.com/exploit-acquisition-program/",
      "notes": "Control row, and a correction to widely-circulated figures. Numerous 2026 secondary sources still cite 'up to $9 million' for Crowdfense; that page has not existed since March 2025. See R34 for the cut itself. The absence of an AI category on the price list of the buyer that prices capability most ruthlessly is a finding, not a gap. Standing caveat: a broker's advertised ceiling is an OFFER and has never been shown to clear at that price."
    },
    {
      "id": "R31",
      "org": "Operation Zero",
      "program": "Published price list",
      "change_type": "context",
      "date_announced": "2026",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Up to $2,500,000 for mobile. Categories: mobile, desktops, servers, routers, baseband, virtualization, web services. NO AI, LLM, or model category.",
      "value_kind": "announced-offer",
      "scope_note": "Offensive broker control row, Russian market.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://opzero.ru/en/prices/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260225203639/https://opzero.ru/en/prices/",
      "notes": "Control row. See confirmed-prices-2026-04.json for the Williams DOJ evidence that Operation Zero's advertised figures and its confirmed clearing prices differ by roughly an order of magnitude."
    },
    {
      "id": "R32",
      "org": "Zerodium",
      "program": "Published price list",
      "change_type": "terminate",
      "date_announced": "2025-02-26",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Price list WITHDRAWN. zerodium.com resolves and returns HTTP 200 with a 2,011-byte placeholder (logo, an email address, a PGP key link), Last-Modified 2025-02-26. The canonical price list at /program.html returns 404. No AI category ever existed on it.",
      "value_kind": "announced-offer",
      "scope_note": "Offensive broker control row. The historic published chart ran $5,000 to $2,000,000.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 2,
      "source_url": "https://zerodium.com/program.html",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20241201062400/https://zerodium.com/program.html",
      "notes": "Corrected 2026-07-28 after a transport-layer probe rather than a single failed fetch. The distinction matters: the site is up, the price list is gone. Zerodium has published no price since 2025-02-26 and no longer functions as a public price-setter. Recorded as withdrawal-of-publication, which the evidence supports, not as company death, which it does not."
    },
    {
      "id": "R33",
      "org": "Multiple (EchoLeak observation)",
      "program": "n/a",
      "change_type": "context",
      "date_announced": "2025",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "ai-behaviour",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "No standing broker price for the class",
      "value_kind": "announced-offer",
      "scope_note": "CVE-2025-32711, a zero-click prompt-injection data-exfiltration issue in Microsoft 365 Copilot, received a CVE and was patched, yet no exploit broker assigns a standing price to that vulnerability class.",
      "stated_reason": null,
      "ai_attributed": "explicit",
      "confidence_tier": 2,
      "source_url": "https://www.microsoft.com/en-us/msrc/bounty-ai",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260719142210/https://www.microsoft.com/en-us/msrc/bounty-ai",
      "notes": "The existence proof that AI-native vulnerabilities can be real, remotely triggered, and consequential, and still be worth nothing on the offensive market. The likely reason is that they are patchable by a prompt change, non-persistent, and unreliable, which is to say they fail every property that makes an exploit an asset."
    },
    {
      "id": "R34",
      "org": "Crowdfense",
      "program": "Exploit Acquisition Program",
      "change_type": "cut",
      "date_announced": "2025-03-30",
      "date_effective": "2025-03-30",
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": "Headline maximum $9,000,000; Mobile up to $9,000,000; Mobile App up to $5,000,000; SMS/MMS full chain zero-click $7,000,000 to $9,000,000; Desktop up to $2,000,000; Virtualization up to $1,000,000",
      "old_value_confidence": 2,
      "new_value": "Headline maximum $7,000,000; Mobile up to $7,000,000; Mobile App category REMOVED; SMS/MMS full chain zero-click category REMOVED; Desktop up to $1,500,000; Virtualization up to $500,000",
      "value_kind": "announced-offer",
      "scope_note": "The only mature Western-facing broker still publishing a list. Change bracketed between the 2025-03-15 snapshot, which still reads $9,000,000, and the 2025-03-30 snapshot, which reads $7,000,000. Unchanged in the sixteen months since.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 2,
      "source_url": "https://www.crowdfense.com/exploit-acquisition-program/",
      "corroborating_url": null,
      "archive_url": "http://web.archive.org/web/20260217085713/https://www.crowdfense.com/exploit-acquisition-program/",
      "notes": "The most consequential correction of this research pass. The received view in 2026 trade press is that offensive ceilings are at record highs; the primary evidence is that the leading published Western list was CUT by 22 percent and had its two highest tiers deleted, in March 2025, and has not moved since. No AI rationale was given, and the cut predates the 2026 defensive repricing wave by roughly a year. The site is actively maintained (blog posts in March and June 2026), so the frozen list is a choice, not neglect. Anyone citing 'Crowdfense pays up to $9 million' in 2026 is quoting a page that has not existed for sixteen months."
    },
    {
      "id": "R35",
      "org": "Advance Security Solutions",
      "program": "Published acquisition prices",
      "change_type": "new-program",
      "date_announced": "2025-08-20",
      "date_effective": "2025-08-20",
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "Any mobile OS $20,000,000; Android $15,000,000; iPhone $15,000,000; Windows $10,000,000; Chrome $5,000,000; Telegram, Signal and WhatsApp $2,000,000 each; Safari $1,000,000; Edge $1,000,000",
      "value_kind": "announced-offer",
      "scope_note": "New UAE and Uzbekistan-linked entrant advertising two to three times Crowdfense's published tiers.",
      "stated_reason": null,
      "ai_attributed": "no",
      "confidence_tier": 4,
      "source_url": "https://techcrunch.com/2025/08/20/new-zero-day-startup-offers-20-million-for-tools-that-can-hack-any-smartphone",
      "corroborating_url": "https://home.treasury.gov/news/press-releases/sb0404",
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "The only rising published numbers anywhere in the offensive market during this period, and they came from an entity sanctioned by OFAC roughly six months after launch, on 2026-02-24. No evidence exists that any of these offers was ever paid. Included precisely because a naive reading of published maxima would treat $20,000,000 as the market's top price; it is an unpaid advertisement from a now-sanctioned entrant."
    },
    {
      "id": "R36",
      "org": "Google Threat Intelligence Group",
      "program": "n/a (threat intelligence)",
      "change_type": "context",
      "date_announced": "2026-05-11",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "defect",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "First observed in-the-wild LLM-assisted zero-day: a two-factor-authentication bypass semantic logic flaw in an open-source web sysadmin tool. Not a memory-corruption chain.",
      "value_kind": "announced-offer",
      "stated_reason": null,
      "scope_note": "AI authorship inferred by the analysts from a hallucinated CVSS score and tutorial-style docstrings left in the exploit. Assessment given: LLM strength is in high-level flaws and hardcoded static anomalies, and models struggle to navigate complex enterprise authorization logic.",
      "ai_attributed": "explicit",
      "confidence_tier": 4,
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "corroborating_url": null,
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "The single most useful offense-side corroboration of the capability-tier argument. When AI finally showed up in a real attack, it showed up at the logic-flaw tier in open-source software, which is exactly the tier the defensive market has been cutting, and nowhere near the memory-corruption mobile chains that command five to seven million dollars."
    },
    {
      "id": "R37",
      "org": "Crowdfense",
      "program": "n/a (broker research blog)",
      "change_type": "context",
      "date_announced": "2026-06-29",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "primitive",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "No price change. A first-party statement from inside a broker about what AI does and does not do.",
      "value_kind": "announced-offer",
      "scope_note": "Crowdfense researchers describing integrating a commercial model into their own n-day research workflow.",
      "stated_reason": "It is very good at the repetitive, mechanical parts of the job... Used that way, it is a genuine force multiplier for vulnerability research. The bugs here did not come from the model deciding on its own what mattered; they came from steering it: asking the right questions, knowing which lead was worth chasing.",
      "ai_attributed": "explicit",
      "confidence_tier": 3,
      "source_url": "https://www.crowdfense.com/apache-activemq-rce-bypass/",
      "corroborating_url": "https://www.crowdfense.com/crowdfense-n-day/",
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "An exploit broker publicly confirming the expert-plus-AI asymmetry from the supply side, while its own published prices stayed frozen. Separately, in March 2026 Crowdfense licensed its weaponised n-day feed into a third party's autonomous AI attack agent, which is a broker productising inventory into an AI system rather than repricing because of one."
    },
    {
      "id": "R38",
      "org": "United States Department of Justice",
      "program": "n/a (court record)",
      "change_type": "context",
      "date_announced": "2026-02-24",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": null,
      "old_value_confidence": null,
      "new_value": "87 months imprisonment; $1,300,000 forfeiture money judgment; $35,000,000 admitted loss to the employer across 8 stolen components. Contracted price was $4,000,000 for seven components after an initial sale at $240,000; realised payment was $1,300,000.",
      "value_kind": "paid",
      "scope_note": "Sentencing of a defence-contractor general manager for selling stolen exploit components to a Russian broker.",
      "stated_reason": "Williams entered into multiple written contracts with the Russian broker, which involved payment for the initial sale of the components, and additional periodic payments for follow-on support.",
      "ai_attributed": "no",
      "confidence_tier": 1,
      "source_url": "https://www.justice.gov/opa/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade",
      "corroborating_url": null,
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "Three things here are load-bearing and mostly absent from coverage. First, contracted price and realised payment diverge roughly threefold, so a single price-per-exploit figure is a category error. Second, the court record confirms exploit sales are structured as subscriptions with follow-on support payments, not one-time transfers, which the maintenance force in the model has always assumed but could not previously cite. Third, $35,000,000 of admitted loss across 8 components implies roughly $4,400,000 to develop each one at a top-tier Western contractor, against $162,500 realised on grey-market resale: a 27-fold gap between build cost and distressed resale, and the strongest build-versus-buy anchor now in either corpus. The restitution hearing set for 2026-05-12 was sealed and its outcome is unverified."
    },
    {
      "id": "R39",
      "org": "Google Threat Intelligence Group",
      "program": "n/a (threat intelligence)",
      "change_type": "context",
      "date_announced": "2026-03-05",
      "date_effective": null,
      "market_side": "offensive-control",
      "object_class": "chain",
      "old_value": "78 zero-days exploited in the wild in 2024; 100 in 2023",
      "old_value_confidence": 4,
      "new_value": "90 zero-days exploited in the wild in 2025. Enterprise technology accounted for 43 of 90, a record 48 percent. For the first time, more exploitation was attributed to commercial surveillance vendors than to traditional state-sponsored espionage groups.",
      "value_kind": "paid",
      "scope_note": "Demand-side context for the offensive market. No pricing disclosed.",
      "stated_reason": "For the first time since we started tracking zero-day exploitation, we attributed more exploitation to CSVs than to traditional state-sponsored cyber espionage groups.",
      "ai_attributed": "no",
      "confidence_tier": 4,
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",
      "corroborating_url": null,
      "archive_url": null,
      "archive_note": "Re-archive at next monthly run.",
      "notes": "In-the-wild zero-day counts rose in 2025 while published broker prices were flat or falling. If AI had collapsed the cost of producing exploits, this is where it would show first, and the composition shift is toward commercial vendors and enterprise targets rather than toward anything AI-specific."
    }
  ]
}
