Opera bug bounty: How vulnerability research is evolving with AI
Hi Opera users!
Browser security is constantly evolving, and so are the ways vulnerabilities are discovered. At Opera, we heavily invest in securing our products and services through the efforts of our dedicated Security team, but we also recognize the valuable expertise that exists out there across the security community.
Building secure products involves responding to threats but also working proactively with security experts to find and fix issues before they can be exploited. Researchers around the world bring diverse skills, tools, and perspectives, making collaboration an important part of strengthening our security.
That’s why Opera runs its own bug bounty program to help identify and address potential security issues more effectively.
If you haven’t heard about bug bounties before, this blog explains what they are, how they work, and why they benefit everyone involved, from users and security researchers, to companies like us.
If you already know the basics, keep reading for a closer look at the impact AI has had on bug bounties, including some interesting insights into why incentivizing and rewarding security researchers continues to play an important role in improving online security, despite the increasing amount of AI-generated submissions.
What is a bug bounty program and why does Opera have one?
Bug bounty programs allow security researchers to privately and safely report potential vulnerabilities through an official channel, with the incentive of a reward. More simply put – the “bug” refers to a flaw or weakness in software, and the “bounty” refers to a possible reward for responsibly reporting a valid security issue.
The goal is not to cause harm, but to help companies fix problems before they can be abused by bad actors. Most users will never directly interact with a bug bounty program, but they benefit from it in the background.
A bug bounty program does not replace secure development, internal testing, code reviews, audits, monitoring, or incident response. Instead, it adds another layer of protection by bringing in external expertise. Now, not every software bug is a security vulnerability – for example, a button not loading correctly or a page displaying the wrong color may be just a regular product bug, but not suitable as a bug bounty submission. A security vulnerability is a weakness found in a system that could potentially affect the confidentiality, privacy, or integrity of a product, service, or user data.
So, the purpose of a bug bounty program is to create structure around this process. It explains what products are in scope, what types of reports are accepted, how researchers should test, and how submissions are reviewed. This helps keep the process ethical, safe, and useful for everyone involved.
Our internal security teams will always work continuously to improve and protect our products. But the internet is complex and no single team can see everything from every angle. Security researchers often think differently: They test unusual scenarios, combine techniques in creative ways, or notice details that automated systems and internal processes might miss. Their outside perspective can be extremely valuable, which is why, by inviting researchers to participate in our bug bounty program, we create a sustainable path for collaboration.
Opera’s bug bounty program is hosted on Bugcrowd, a platform used by many organizations to manage responsible security reporting. Researchers can use the program to submit eligible findings related to Opera products and services that are included in the program scope.
How does the bug bounty program typically work?
When a researcher finds a potential vulnerability in an Opera product that is part of the bug bounty program, they can submit a report through Bugcrowd. A good report usually includes clear details about the issue, how it was found, what product or service it affects, and steps that help the security team reproduce the problem.
The more precise and responsible the report is, the easier it is for the team to investigate. Once a report is submitted, it is first triaged by Bugcrowd and then forwarded to Opera’s Security team to determine whether the issue is valid and whether it falls within the program’s scope. If the issue is confirmed, Opera can assess its severity and begin working on a fix.
Some reports may describe real vulnerabilities. Others may turn out to be expected behavior, duplicate reports, out-of-scope issues, or problems that come from third-party components. This review process is important because it helps separate genuine security risks from general bugs or unsupported claims.
When a valid issue is found and fixed, users benefit from the improvement, often without ever knowing that the bug bounty process happened behind the scenes. Meanwhile, the submission owner may get financially rewarded for their efforts, depending on varying factors such as the threat level of their discovered vulnerability.
How has the rise of AI affected bug bounty submissions?
Since the widespread adoption of AI, the amount of security research being conducted has drastically increased. AI enables security researchers to accelerate vulnerability discovery and analysis, making the research process significantly more efficient, to the point where some stages can be completed with little to no manual effort.
At the same time, AI has lowered the barrier to entry for bug bounty programs. People with little or no security research experience can use AI to identify potential vulnerabilities and quickly generate reports that are ready to submit, in the hope of receiving a financial reward – even though the reported issues may be inaccurate, low quality, or not represent genuine vulnerabilities.
Parts of the security community have opined that due to AI, bug bounty submissions have declined in quality. For example, AI can mistake regular, non-threatening bugs as vulnerabilities, hallucinate them, or even repeat resolved ones that were submitted in the past. Some might call such submissions part of the “AI slop” phenomenon.
As a result, some companies have decided to end their bug bounty programs and stop paying rewards for submissions, suggesting that reviewing and assessing each submission, only to reject many of them, has become a substantial burden on security teams and a drain on their resources. Instead, they direct security researchers to report vulnerabilities through more direct means of communication, with no monetary rewards being offered for valid submissions.
Why Opera is sticking with its bug bounty program
While we agree that there has been an increase in lower-quality, AI-generated reports and an overall rise in bug bounty submissions, Opera’s own figures show that the acceptance rate of submissions has also increased. This means the growth is not just due to receiving more reports, but also identifying more valid and actionable vulnerabilities. The increase in accepted reports suggests that at least some AI-assisted submissions are contributing meaningful findings rather than simply creating additional noise.

To add, AI is unlikely to be the only factor driving this trend for Opera. During the same period, we also expanded the scope of our bug bounty program, giving researchers more areas to investigate and increasing the opportunities for valid submissions. So it’s fair to say that the rise in both submission volume and accepted reports is likely the result of multiple factors, and there is still clear value coming out of this for Opera users.
From a resource and efficiency perspective, by using the Bugcrowd platform, submissions are reviewed by their team before being forwarded to us. This means our Security team typically receives submissions that have already been checked and filtered, allowing us to focus directly on investigating and addressing valid security issues.
So, what does this mean for the future of Opera’s bug bounty?
Our commitment to the bug bounty program and the security research community remains unchanged.
While AI has increased the volume of submissions, our statistics also show a clear increase in valid and accepted reports. Simply put, we will continue to operate our bug bounty program and reward researchers for legitimate vulnerability submissions. AI may change how vulnerabilities are discovered, but it does not replace the expertise, creativity, and responsible disclosure practices that skilled security researchers provide.
We still believe that bug bounty programs promote a healthier security culture by encouraging responsible disclosure and giving researchers incentive to report vulnerabilities privately, allowing organizations to address issues before details become public and reducing risks for users.
As always, stay safe out there!






