
Crypto teams are experiencing a dramatic surge in bug bounty submissions as artificial intelligence tools make code scanning and report generation easier. According to reports from Cointelegraph, Barry Plunkett, co-CEO of Cosmos Labs, reported a 900% increase in submission volume over the past year, with the company now receiving 20-50 submissions per day. The rise includes both valid and invalid reports, creating additional work for teams trying to separate real security issues from weak claims.
While AI tools have made it easier for researchers to join bounty programs and submit findings, they have also introduced quality concerns. As reported by Cointelegraph, Kadan Stadelmann, chief technology officer at Komodo Platform, noted an increase in low-quality bug bounty submissions and false positives, potentially suggesting AI sourcing. Stadelmann explained that AI may have lowered the cost and effort required to produce a report, leading to more submissions overall. This trend mirrors broader concerns, as Daniel Stenberg, creator of curl, ended his bug bounty program after dealing with what he described as an influx of 'AI slop in vulnerability reports'.
In response to the growing volume, crypto teams are implementing stricter review processes and triage systems. According to Cointelegraph reports, Cosmos Labs has tightened how it scores incoming reports and now gives more weight to trusted researchers with a strong record. The company is also working with bug bounty providers that offer more advanced triage support to help reduce time spent reviewing weak or duplicate submissions. These changes demonstrate teams' efforts to maintain the utility of bounty programs while managing the additional load created by AI-assisted reporting.
The trend extends beyond crypto, with HackerOne reporting 85,000 valid bounty submissions in 2025, up 7% from the previous year. As reported by Cointelegraph, Stadelmann suggested that blockchain teams will have to create AI deterrents to sift through incoming bug bounties, particularly benefiting smaller teams with fewer engineers available to review large numbers of submissions. He added that defensive AI systems could help sort reports and reduce the burden on internal teams, while protocols may need stricter submission standards to lower the number of weak reports as AI tools continue to spread across the industry.