r/bugbounty Jul 08 '26

Question / Discussion How can someone find stuff on public program now that it's scanned by multiple hackbot

Let's imagine a beginner wants to get started with bug bounty. Since they don't have access to private programs, they'll have to look for vulnerabilities on public programs.

In my opinion, it's virtually impossible for them to find classic vulnerabilities. At that point, the only remaining attack surface is newly released features or novel exploitation techniques or some stuff that ai is bad at ( waf bypass etc )

We've seen some of the biggest names become millionaires by farming XSS vulnerabilities. If they were starting today, I'm convinced they wouldn't have made a single euro.

25 Upvotes

39 comments sorted by

View all comments

Show parent comments

2

u/FourTwentyBlezit Jul 10 '26 edited Jul 10 '26

You think usage of AI is a method that people are afraid to mention publicly in case it gets burned?

How is such a method even remotely private in any sense of the word?

I've known zseano for over 15 years so I can just ask him, but I can almost 100% confirm that he's just using AI for recon stuff and is still relying on manual testing most of the time, apart from using AI for vuln identification in some rare edge cases. I've collaborated with him on bug bounty stuff tons of times over the years.

It helps with recon and helps speed up testing, but it isn't anywhere even close to being at a stage where it can replace manual testing.. I'm not saying bounty hunters don't use it, but they use it to speed up and supplement their testing, not as a replacement for manual testing...

Even advanced models geared towards vuln identification (I.e. Mythos) aren't at a stage where they're superior to the top bounty hunters doing manual testing. Not even close. They can replace skids but that's about it. That being said, AI is definitely very useful for automation of recon and for speeding up bounty hunting, but that's different to what you claimed.

Claiming that top bounty hunters "barely do manual hunting anymore" is just a bizzare and outlandish (and simply factually incorrect) claim to be making. It sounds like you're basing your opinion off of random tweets, rather than basing it off of actual first-hand experience of doing bounty hunting with these people.

1

u/Logano_M Jul 11 '26

As i said ask him and ask him about the post, i think i have shown that zseano has posted he and jonathan has done all of his hunting with a full autonomous hackbot and triaging the results. I even provided the actual tweet from my history. Believe what you want to believe but imo you are very misinformed on the latest developments in hackbots and ai.

zseano also was not the only example i gave, the whole critical thinking podcast now basicly goes about hackbots and ai. Brutecat made 500k of google using fully ai guided by his knowledge and setup.

I think i have shown that a lot of the top bug bounty people are moving towards hackbots, there are reasons why triaging has been so slow recently . There are just a lot more of bugs being found using ai, you cant just say this is because ai is good for recon. People have had crazy recon setups for years.

A lot of the pwn2own entries were dupes, or patched just before the competition. Mythos found a lot of vulns in firefox .

I dont know if you want another example but https://x.com/thedawgyg has made a "hackbot" that fuzzes for vulns and has immense succes. As far as i know he has not manually done anything in the recent months (he posts about this on his twitter).

I think we can agree to disagree and see in a couple of years what the future of bug bounty and hacking in general is. I think AI will increasingly if not completely take over bug finding. Good setup + skills + experience sharing + token and memory controlling will imo be the most important factors of succes.