AI Security Intelligence

Published benchmark scores from peer-reviewed research — 52 results across 3 categories. Plus 31 active bug bounty programs.

Model Security Leaderboard

Autonomous bug patching

SWE-bench Verified score — the industry standard for autonomous code repair. Models are given real GitHub issues with failing tests; score = % resolved with no human help.

Model
Score
1
93.9%
2
84.2%
3
83.1%
8
80.2%
10
78.9%
11
78.8%
12
78.8%
13
78.0%
14
77.4%
15
77.2%
17
77.2%
19
74.4%
21
73.4%
22
73.4%
28
68.5%
30
63.2%
31
60.5%
34
56.1%
40
49.0%
All scores are from published peer-reviewed papers or official technical reports. Hover any score's source column to see the full citation. New results are added automatically every 6 hours as they are published.

DARPA AI Cyber Challenge (AIxCC)

Official site ↗

The most credible real-world AI security competition. Autonomous Cyber Reasoning Systems (CRS) analyze millions of lines of code to find and patch vulnerabilities — with no human intervention.

54
Vulns Found
of 63 synthetic
43
Vulns Patched
68% success rate
18
Real-World Vulns
discovered by teams
$152
Avg Cost/Task
vs $1000s traditional
1
Team AtlantaGeorgia Tech, Samsung Research, KAIST
$4M
2
Trail of BitsNYC-based security firm
$3M
3
TheoriUS & Korea security researchers
$1.5M

Notable AI Security Discoveries

All security news →

Active Bug Bounty Programs

ProgramOrganizationPlatformAI PolicyMax PayoutScope
ImmunefiImmunefi (platform)ImmunefiAI Encouraged$10MDeFi protocols, smart contracts, Web3 bridges, DAO treasuries
HackerOne ProgramsHackerOne (platform)HackerOneCase by Case$1M1,000+ programs across tech, finance, government, healthcare
Apple Security BountyAppleDirectNot Specified$1MiCloud, iOS, macOS, Safari, Apple silicon firmware
Bugcrowd ProgramsBugcrowd (platform)BugcrowdCase by Case$500K1,000+ programs — tech, finance, automotive, healthcare
Meta Bug BountyMetaHackerOneAI Allowed$300KFacebook, Instagram, WhatsApp, Threads, Messenger, Meta Quest
Binance Bug BountyBinanceHackerOneAI Allowed$250KBinance.com, mobile apps, exchange API, Binance Smart Chain, Binance Pay
Microsoft Bug BountyMicrosoftDirectAI Allowed$250KAzure, Microsoft 365, Windows, Xbox, Edge, Bing
Google DeepMind AI SafetyGoogle DeepMindDirectAI Encouraged$250KGemini models, Google AI APIs, Vertex AI, AI Studio
Coinbase Bug BountyCoinbaseHackerOneAI Allowed$250KCoinbase.com, Coinbase Pro, Coinbase Wallet, exchange APIs
Vulnerability Reward ProgramGoogleDirectAI Allowed$250KGoogle Search, Google Cloud, Android, Chrome, YouTube, Gmail
Ethereum Foundation Bug BountyEthereum FoundationDirectAI Encouraged$250KEthereum protocol, EVM, consensus clients (Prysm, Lighthouse, Teku, Nimbus), execution clients (Geth, Nethermind, Besu)
Samsung Mobile Security RewardsSamsungDirectAI Allowed$200KSamsung Galaxy devices, Knox, One UI, Samsung Health, Samsung Pay, Bixby
Kraken Bug BountyKrakenBugcrowdAI Allowed$100KKraken.com, Pro Trading, mobile apps, exchange API, Kraken NFT
GitHub Security Bug BountyGitHub (Microsoft)HackerOneAI Allowed$100KGitHub.com, Actions, Packages, Codespaces, Copilot
OpenAI Bug BountyOpenAIBugcrowdCase by Case$100KChatGPT, API (GPT-4o, o3, o4), DALL-E, Sora, OpenAI.com
Stripe Bug BountyStripeHackerOneAI Allowed$50KStripe.com, Dashboard, API, Connect, Terminal, Stripe.js, mobile SDKs
Shopify Bug BountyShopifyHackerOneAI Allowed$50KShopify.com, Admin, Partner API, Storefront API, POS
xAI Bug BountyxAIBugcrowdCase by Case$50KGrok models, grok.com, xAI API, X AI integrations
Anthropic Bug BountyAnthropicHackerOneCase by Case$50KClaude.ai, Anthropic API, Claude models
Snap Bug BountySnap Inc.HackerOneAI Allowed$35KSnapchat, Snap Map, Spotlight, Lens Studio, Snap Kit, Bitmoji
PayPal Bug BountyPayPalHackerOneAI Allowed$30KPayPal.com, Venmo, Braintree, PayPal Checkout APIs
Hack the PentagonUS Department of DefenseHackerOneCase by Case$25KDoD public-facing websites, military branches, DISA systems
Mistral AI Bug BountyMistral AIDirectAI Encouraged$25KMistral API, Le Chat, open-weight model deployments
Atlassian Bug BountyAtlassianBugcrowdAI Allowed$25KJira, Confluence, Bitbucket, Trello, Atlassian Cloud
HackerOne Bug BountyHackerOneHackerOneAI Encouraged$25KHackerOne.com, API, Hacker Dashboard, Customer Portal, Pentest Platform
Discord Bug BountyDiscordHackerOneAI Allowed$20KDiscord.com, desktop/mobile apps, Bots API, Activities, Discord Store
Netflix Bug BountyNetflixBugcrowdAI Allowed$20KNetflix.com, mobile/TV apps, API, Partner portal, Open Connect CDN
X (Twitter) Bug BountyX Corp.HackerOneNot Specified$15KX.com, mobile apps, X API, X Premium, Spaces, Communities
Tesla Bug BountyTeslaBugcrowdNot Specified$15KTesla vehicles (OTA, infotainment), Tesla.com, mobile apps, energy products
Verizon Bug BountyVerizonBugcrowdNot Specified$10KVerizon.com, My Verizon app, Fios, VZ Media, Visible
BMW Vulnerability DisclosureBMW GroupDirectNot SpecifiedVariesBMW Connected Drive, My BMW App, vehicle telematics, ISTA diagnostic systems

AI tools policy reflects publicly stated program rules where available. Always read individual program scope before submitting. “AI Encouraged” means the program explicitly welcomes AI-assisted research.

Payout Estimator

Estimate potential earnings from AI-assisted bug bounty research. Pick a model and program, adjust your hours and API costs.

10h
$5

Select a model and program above to see estimated earnings

Estimates are illustrative only. Actual results depend on target complexity, researcher skill, vulnerability severity distribution, and program-specific acceptance criteria. The model uses benchmark scores as a proxy for bug-finding capability — real-world performance may differ significantly.