August 2, 2026·4 min read·AIgentic.media

AI Slop Broke Apple's $200K Bug Bounty

ai-newssafetyapplebug-bounty
AI Slop Broke Apple's $200K Bug Bounty

The Cap that Caught $200K

AI is a cybersecurity risk, just not in the way most people expect. Apple has started capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period between submissions. The reason isn't a shortage of vulnerabilities. It's a flood of AI-generated reports so bad they're drowning the real ones.

The Financial Times reports that Apple's bug bounty program is overrun with low-quality, AI-fabricated security reports. Hallucinated vulnerabilities. Fake exploits. Reports that look real enough to need human review but are entirely made up. The volume has gotten so high that Apple had to impose submission limits per researcher.

Then the real cost showed up.

The One that Got Away

Italian cybersecurity startup Bynario used ChatGPT to discover a genuine macOS vulnerability -- the kind that gives an attacker full control over a target machine. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. It was a serious finding by any measure.

But Bynario couldn't report it. Apple had already blocked further submissions from the company's account because the cap had been reached.

The irony writes itself. Bynario used an AI tool to find a real vulnerability, but the same kind of AI-generated content -- less competent and infinitely more plentiful -- had already clogged the pipeline so thoroughly that the real discovery couldn't get through. Apple has since reached out to Bynario and is reviewing the vulnerability. But the fact that it slipped through at all is a warning sign about what happens when AI slop meets security infrastructure.

AI security researcher at a terminal, surrounded by a flood of error messages

AI vs. AI: Apple Fights Fire with Fire

Apple isn't sitting still. The company is itself using AI models from Anthropic and OpenAI to hunt for vulnerabilities internally. Its latest round of security updates included five times as many fixes as usual -- a signal that the AI-driven discovery pipeline is producing results, at least when the AI is being used by the platform owner rather than by random researchers.

But this creates a strange dynamic. Apple benefits from AI-powered vulnerability discovery when it controls the tools. It gets overwhelmed when the same technology is used by outsiders, even well-intentioned ones. The distinction between AI as a security tool and AI as a security problem depends almost entirely on who is holding the prompt.

The broader question for bug bounties

Rafe Pilling of Sophos told the FT that bug bounty programs have shifted from finding vulnerabilities to validating them "at machine speed." The role of the human researcher is no longer about discovering flaws -- it's about proving that AI-generated findings are real, one by one.

This raises uncomfortable questions about whether traditional bug bounty models can survive. If the ratio of fake to real reports keeps climbing, platforms either spend more on triage or start treating every submission as suspect. Both paths degrade the value proposition for legitimate researchers. And as the Bynario case shows, the hardest-hit may not be the platforms themselves, but the researchers who actually find things worth paying for.

Nuance

The AI-generated report problem is real, but it's not a death sentence for bug bounties. Apple's cap is a blunt instrument, and the company has shown willingness to work around it when contacted directly (as with Bynario). The deeper issue -- that AI makes it trivially cheap to produce security theater at scale -- is one every major platform will need to solve. Better automated triage, reputation-based submission systems, and AI-to-AI verification pipelines are all being explored. But for now, a $200K vulnerability sat in limbo because the inbox was too full of nonsense to see it.

Sources

Want to learn more?

Let's discuss how AI can transform your business.

Get in Touch