GitHub 漏洞賞金砍半:AI 洗版報告惹的禍 | GitHub Bug Bounty Cut in Half: Blame AI Slop Reports
By Kit 小克 | AI Tool Observer | 2026-07-25
🇹🇼 GitHub 漏洞賞金砍半:AI 洗版報告惹的禍
GitHub 漏洞賞金從 2026 年 7 月 27 日起全面砍半:Critical 等級從過去的 2 萬到 3 萬美元以上,直接砍到固定 1 萬美元,公開賞金計畫史上最大幅度縮水。原因不是預算不夠,而是 AI 洗版——大量用 AI 工具自動產生的「漏洞報告」灌爆了 GitHub 資安團隊的審核佇列,逼得他們不得不重新設計整套獎勵制度。
GitHub 為什麼砍漏洞賞金?
GitHub 官方部落格直言,近期收到「大量沒有實際安全影響」的提交:沒有 PoC(概念驗證)、經不起檢驗的理論攻擊情境,甚至是早就列在「不受理清單」上的舊問題。這些報告有不少一看就是 AI 生成——格式工整、術語齊全,但實測完全打不穿系統。審核一份要花人力,獎金卻是給真正有影響力的漏洞,結果變成劣幣驅逐良幣。
AI 洗版問題有多嚴重?
GitHub 不是唯一受害者。curl 專案更早前也宣布考慮收掉漏洞賞金計畫,理由同樣是「AI 垃圾報告淹沒維護者」。這反映一個現實:當生成式 AI 讓「寫一份看起來像樣的資安報告」變得幾乎零成本,懸賞制度原本用來吸引真正研究員的誘因,反而被拿去大量刷單。
新制度長怎樣?公平嗎?
- 公開賞金:全面砍半,Critical 固定 1 萬美元
- VIP 邀請制:永久受邀的資深研究員,獎金維持 3 萬美元以上,還能更快拿到回覆、更直接接觸資安工程團隊
- 舊案不受影響:7/27 前送出的報告(含已在佇列中的),沿用舊制獎金
換句話說,GitHub 賭的是「用更少但更精準的獎勵,留住真正厲害的研究員」,把資源從海量低品質提交,轉移到少數高信任度的關係上。
對開發者與資安研究員代表什麼?
如果你是靠 Bug Bounty 賺外快的資安愛好者,這是一個警訊:光靠 AI 產出報告去廣灑漁網的時代要結束了,平台開始用信譽和實績篩人。如果你是維護開源專案的開發者,curl 和 GitHub 的案例都在提醒你,漏洞獎勵制度也需要防禦「AI 濫用」的機制,不然團隊會被無效報告拖垮。
常見問題
Q: GitHub 漏洞賞金什麼時候調整?
A: 2026 年 7 月 27 日生效,之前送出的報告維持原獎金標準。
Q: 為什麼會有這麼多 AI 生成的假漏洞報告?
A: 生成式 AI 讓寫出「看起來專業」的資安報告幾乎零成本,但缺乏真實測試與 PoC,導致大量無效提交。
Q: 新的 VIP 制度所有人都能加入嗎?
A: 不行,VIP 是永久邀請制,只開放給 GitHub 認定信譽良好、實績佳的資深研究員。
好不好用,試了才知道。
🇺🇸 GitHub Bug Bounty Cut in Half: Blame AI Slop Reports
Starting July 27, 2026, GitHub is cutting its public bug bounty payouts by at least half across every severity tier — Critical findings drop from $20,000–$30,000+ down to a flat $10,000. It's the biggest cut in the program's history, and the driver isn't budget — it's AI slop: a flood of AI-generated "vulnerability reports" that swamped GitHub's security triage queue and forced a full rework of the reward system.
Why Is GitHub Cutting Bug Bounty Payouts?
GitHub's security blog says it's seeing "a sharp increase in submissions that don't demonstrate real security impact" — no proof-of-concept, theoretical attack scenarios that fall apart under scrutiny, or issues already on the published ineligible list. Many read as AI-generated reports: polished formatting, correct jargon, zero actual exploit. Triaging each one costs real engineer-hours, while the payout structure kept rewarding volume over verified impact.
How Bad Is the AI Slop Problem?
GitHub isn't alone. The curl project announced it's considering shutting down its own bug bounty program for the same reason — maintainers say AI-generated junk reports are burying them. The pattern is simple: once generative AI makes writing a plausible-looking security report nearly free, the incentive that was supposed to attract real researchers gets farmed instead.
What Does the New System Look Like?
- Public tier: payouts cut in half, Critical fixed at $10,000
- Invite-only VIP tier: established researchers keep $30,000+ rewards, plus faster response times and direct access to the security engineering team
- Grandfathered reports: anything submitted before 7/27, including reports already in the triage queue, keeps the old payout terms
The bet is straightforward: fewer, sharper rewards aimed at researchers with a track record, instead of spreading money thin across a flood of low-quality noise.
What This Means for Developers and Security Researchers
If you rely on bug bounty income, this is a signal — mass-producing reports with AI and hoping something sticks is losing ground fast, as platforms start filtering by reputation and track record instead. If you maintain an open-source project, GitHub and curl are both showing that bounty programs now need defenses against AI abuse, or the triage burden will crush the team running them.
FAQ
Q: When does GitHub's bug bounty cut take effect?
A: July 27, 2026. Reports filed before that date keep the previous payout terms.
Q: Why are there so many fake AI-generated vulnerability reports?
A: Generative AI makes it nearly free to write a professional-looking security report with no real testing or proof-of-concept behind it, flooding triage queues with invalid submissions.
Q: Can anyone join the new VIP tier?
A: No — it's permanent invite-only, reserved for researchers GitHub already trusts based on track record.
好不好用,試了才知道。(Does it actually work? Only one way to find out.)
Sources / 資料來源
- GitHub Blog: Next chapter - Restructuring GitHub's bug bounty program
- The Hacker News: GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
- The Register: GitHub slashes public bug bounty payouts as AI report flood buries its security team
常見問題 FAQ
GitHub 漏洞賞金什麼時候調整?
2026 年 7 月 27 日生效,之前送出的報告維持原獎金標準。
為什麼會有這麼多 AI 生成的假漏洞報告?
生成式 AI 讓寫出看起來專業的資安報告幾乎零成本,但缺乏真實測試與 PoC,導致大量無效提交。
新的 VIP 制度所有人都能加入嗎?
不行,VIP 是永久邀請制,只開放給 GitHub 認定信譽良好、實績佳的資深研究員。
延伸閱讀 / Related Articles
- GitHub Copilot 導入 Kimi K2.7 Code:首款開源模型上線 | GitHub Copilot's First Open-Weight Model: Kimi K2.7 Code
- IsoDDE 解析:Isomorphic Labs AI 藥物設計贏 AlphaFold 3,FDA核准仍是零 | IsoDDE: Isomorphic Labs' AI Beats AlphaFold, Zero FDA Nods
- Gemini CLI 淪駭客利器:AI 寫出 89% 攻擊程式碼實錄 | Gemini CLI Hijacked: AI Wrote 89% of a Real Botnet Attack
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言