Turso has officially retired its bug bounty program as of January 17, 2026. The software vendor cited a flood of low-quality submissions generated by autonomous AI agents as the primary reason for this decision. The team stated that most issues labeled as critical were nonsensical and lacked any understanding of the codebase.
Software vendor cites flood of low-quality submissions from autonomous agents
The retired program previously awarded $1,000 for bugs leading to memory corruption. Developers reported that many of these submissions were merely AI slop created by pointing large language models at the project. The influx of automated noise made it difficult to distinguish genuine security vulnerabilities from generated content.
Turso implemented an automated system to close suspected bot submissions before they reached human reviewers. This measure failed to stop the issue because the bots continued to open new issues for manual review. The project is not shutting down contributions entirely but is removing the financial incentive to reduce AI-generated noise.
The decision highlights the growing challenge of maintaining open-source software quality in the age of generative AI. Autonomous agents can now generate code and reports at a scale that overwhelms traditional triage processes. This shift forces projects to reconsider how they handle external feedback and security reporting.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.