The World of Bug Bounty, June 3th, 2026: An Ugly Public Feud between Nightmare-Eclipse and Microsoft, Triage Getting Attention, and More.
World of Bug Bounty, Issue #2.
Welcome to our 2nd issue. I appreciate all the feedback and pointers! If you have feedback or pointers, submit them below.
To say it’s a busy month in the world of bug bounty is an understatement. There’s the public feud between Microsoft’s Vulnerability Reporting Program and Nightmare-Eclipse which include multiple zero-days, HackerOne completely changing their triage process, and bug bounty being squeezed by AI, including thoughts from Chompie (Berlin Pwn2Own).
The Triage Problem
Triage is a core aspect of the bug bounty process. A good triage experience is crucial for researchers. For a researcher, the effort and time spent is unrewarded until the program accepts the issue as valid. For a program, it’s essential to triage promptly and properly - for the right and valid reports to move along the process to be fixed and to respond quickly to valid findings. With criticals and highs, companies cannot afford to keep those waiting in queues. Prior to AI, triage was ok - not great. But with AI, triage is now becoming unmanageable both for researchers and for programs.
One researcher’s perspective: Shubs (co-founder of AssetNote and researcher) notes that their experience has “degraded to a point” where they don’t want to submit their reports now. They point at how they sent in a report in April that took 12 days before a human responded.
From Linus Torvalds’s perspective: Linus Torvalds (of Linux fame) stated that the “flood of AI reports” has made the “security list almost entirely unmanageable”. Linus notes that there’s a lot of duplication of people finding the same issues with the same tools.
Triage is now such a pressing issue that platforms are reacting. HackerOne is fundamentally changing their triage process. Previously, HackerOne treated all submissions the same. A new researcher and an experienced hacker’s report were treated the same in triage. Now, they’re stating that most reports will face prioritization. High severity reports from established researchers will supposedly be routed to human reviewers within hours. Their goal is to apply this process to 100% of submissions by the end of July 2026.
Researcher vs Programs: Microsoft and Nightmare-Eclipse
The ugly side of bug bounty is coming out. Bug Bounty requires an implied contract between both the researcher and the program: that both will treat the other with respect. Things like coordinated disclosure, timely communication, fair bounties and explanations, all fall within that implied contract.
It’s ugly between Microsoft and Nightmare-Eclipse. I don’t see publicized communication so it’s hard to say exactly what’s happened. This is what we know: Nightmare-Eclipse has disclosed multiple zero-day exploits since April 2026. Microsoft published a blog post on May 27th referencing their Digital Crimes Unit and “coordinating as needed with law enforcement.” While not explicit, it could be seen as a threat. Nightmare-Eclipse claimed Microsoft deleted their MSRC account and also their Github account. The researcher also now claims that other researchers have given them free vulnerabilities and that on July 14th, “I will make sure your bones are shattered that day.”
On Monday, June 1st. Microsoft Security Response Center published the following on X: “To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”
Ultimately, it’s hard to say what exactly happened without transparency from MSRC or the researcher and what exactly soured the relationship. What we do see is the security community responding to Microsoft’s handling of the situation and a strong example of the fragility of the bug bounty world.
Impact of AI on Bug Hunting
Multiple Platforms published posts on how AI is enhancing bug hunting. While this feels more like marketing, they’re evidence that AI has arrived. These posts all read as enhancing bug bounty and not killing bug bounty. YesWeHack states that “Proof that AI hasn’t replaced Bug Bounty, it’s amplified it” while BugCrowd’s own CEO states “AI can accelerate repeatable work. Humans bring creativity and context. Trust comes from combining both. That is the future Bugcrowd is building.”
While platforms like BugCrowd and YesWeHack have good reason to ensure bug bounty doesn’t die, the foreseeable future will have AI-enhanced bug hunters who use AI to accelerate time to value.
Low Hanging Fruit: Gone
Another impact from AI is that the low hanging fruit in bug bounty hunting is disappearing. The human aspect is still necessary for complex chained bugs, but low hanging fruit is becoming harder to hunt.
From Berlin’s Pwn2Own competition, Chompie told BBC that she thought this year’s Pwn2Own may be her last chance. She states that “…a lot of the lower-hanging fruit will start to go away.” From ZeroDay Initiative who runs Pwn2Own, they noted that May 2026 follows the largest monthly release in Microsoft’s history and is indicative of industry trend of submission numbers growing.
We’ve seen programs adjusting. Recently, one private program eliminated their low tier of bounties, committing to only pay for mediums and above. Another program paused, citing “resource constraints”.
Conclusion
The million-dollar (or more) question: what is the future of bug bounty? Stress-tested triage triggering platform-wide changes. Broken researcher-program relationships. AI fundamentally changing the economics of hunting. The pressure is building. Stay tuned, we'll be watching.


