AI slop forces Turso to shut down its bug bounty program
Rust-based SQLite-compatible database Turso retired its bug bounty, which paid $1,000 per critical vulnerability. Most submissions were LLM-generated: the flaws did not reproduce and some "exploits" required editing Turso's own source code. Maintainers spent hours triaging reports no human had actually written.
- Turso paid $1,000 per critical vulnerability for about a year
- One report claimed arbitrary SQL execution against a SQL database
- Another "bug" required recompiling Turso with modified source code
- Generating a report with a frontier model costs about a tenth of a cent
Read next
Software