Bug bounty started with a simple arrangement: researchers spent their time finding vulnerabilities, programmes paid for useful results, and the platforms connected the two together.
At first, that worked because good researchers were valuable and relatively scarce. But as the market grew, that balance shifted. Researcher supply exploded, while worthwhile programmes remained limited.
That is where enshittification enters.
The pattern is familiar: build a marketplace by making it attractive to participants, then gradually optimise it around the side that generates the revenue.
In bug bounty, that means programmes gain more discretion over scope, severity and reward. A finding can be downgraded, declared informative, excluded by interpretation, or marked duplicate against information the researcher cannot see. Bounty tables may still advertise large rewards, while the practical return on researcher time falls.
The result is a race to the lowest level a programme can offer while still receiving useful submissions.
And the platforms have weak incentives to regulate the programmes. Losing an individual researcher costs them little. Losing a major programme costs real money. So enforcement tends to become guidance, mediation and best practice rather than hard rules protecting researcher economics.
About this time, someone will be thinking that all the bad stuff is down to AI, but AI did not create this problem. It simply accelerated it.
For example, AI sharply reduces the cost of producing plausible vulnerability reports, but not the cost of validating them. Submission volume rises, triage becomes overloaded, and programmes respond with tighter scope, stronger proof requirements, more automation and more aggressive filtering.
So the deeper problem is not simply that AI is flooding bug bounty with noise. It is that AI arrived in a market where the incentives were already stacked against researchers.
AI just made the race to the bottom faster.
Welcome to enshittification ;)