Curious if other builders here have noticed this over the past couple of weeks.
For our project, Owl Browser, we set up a small bug bounty program to encourage responsible disclosure. The idea was simple: if someone finds a legitimate exploit, we want to know about it and we are happy to pay out for it.
Recently though, our inbox has been completely overrun with self-described cybersecurity researchers sending what are clearly automated ChatGPT templates. They run basic reconnaissance tools against our domain, find something trivial like an informational DNS record or a missing HTTP header, mark it as "HIGH SEVERITY", and paste a massive generic remediation guide asking for payment. Nobody is reading the scope documentation.
I really do not want to kill the program because working with legitimate researchers is valuable, but triaging dozens of hallucinated reports every week is eating up real dev hours.
If you run a public disclosure policy or bounty for your project, how do you handle triage? Have you added specific proof-of-concept requirements or intake filters that actually keep the low-effort spam out?
Source: r/SideProject · by /u/ahstanin