Technology

Story: HackerOne Logs 85,000 Valid Bug Reports in 2025 as AI Tools Flood Platforms

By Bruce Buterin

1 / 15

AI Sharpens Detection but Muddies the Water. Artificial intelligence changed the game for bug hunters in 2025.

2 / 15

Filtering Gets Harder as Volume Climbs. The 7% uptick sounds modest. It's not. When you're already processing tens of thousands of…

3 / 15

HackerOne pulled in 85,000 valid bug bounty submissions last year. That's a 7% jump from 2024, and the company's pretty clear about what drove it: artificial intelligence.

4 / 15

The bug bounty platform, one of the biggest in the space, saw AI reshape how security researchers hunt for vulnerabilities. More tools meant more reports.

5 / 15

Artificial intelligence changed the game for bug hunters in 2025. Researchers leaned hard on AI-powered scanners and analysis tools to spot flaws in code.

6 / 15

But there's a flip side. The same tools that boost efficiency also flood the system. Not every AI-flagged issue turns out to be a real problem. Some submissions lack context.

7 / 15

Bug bounty programs depend on quality, not just quantity. A thousand mediocre reports don't help if the real critical vulnerabilities get buried in the pile.

8 / 15

The 7% uptick sounds modest. It's not. When you're already processing tens of thousands of submissions annually, even a small percentage increase means thousands more reports to…

9 / 15

Platforms like HackerOne typically use a mix of automated checks and human reviewers to assess incoming reports.

10 / 15

AI-generated reports complicate that workflow. They often look legitimate on the surface. The language is technical. The formatting is clean. But the substance can be thin.

11 / 15

No clear word yet on how HackerOne plans to tackle the slop problem. The company hasn't announced new filtering tech or changes to its submission guidelines.

12 / 15

The researcher community embraced AI hard in 2025. Tools like GitHub Copilot, ChatGPT, and specialized security scanners became standard kit for bug hunters.

13 / 15

See also: Fake Cops Force Victim to Hand Over $1 Million in Bitcoin During Brazen Home Invasion

14 / 15

It's faster work, basically. A researcher can scan multiple targets in the time it used to take to manually probe one. That efficiency explains part of the submission surge.

15 / 15

But speed doesn't always equal skill. Veterans in the bug bounty scene worry that AI lowers the barrier to entry too much.

The Currency Analytics

Want the full story?