bug bounty
A standing offer from a company: find a security hole in our product, tell us instead of selling it, and we pay you.
A bug bounty is a deal between a company and the world’s security researchers. Find a flaw in our software, report it to us privately, and we will pay you for it. The payout scales with severity, and a serious flaw in a widely used operating system can be worth six figures. The point is to make honest disclosure more attractive than the alternative, which is selling the same flaw to someone who plans to use it.
The model worked well for two decades and is now under strain. Every report has to be read and verified by a human, and language models made it very cheap to produce something that looks like a competent report without being one. Apple, among others, has started capping how many submissions each researcher can file, which protects reviewers but also means genuine findings sometimes cannot get through the door.