Vulnerability Disclosure as a Signal: Effects on Submission Volume and Validity in Bug Bounty Programs
Posted: 30 Jul 2024 Last revised: 19 Feb 2026
Date Written: February 18, 2026
Abstract
As cyberattacks pose increasing financial risks, organizations are turning to bug bounty programs to crowdsource vulnerability discovery. However, program effectiveness is often weakened by hackers’ uncertainty about firms’ internal criteria for judging a reported vulnerability’s validity, that is, whether it creates a meaningful security risk in the firm’s specific context and qualifies for a reward. A key feature of these programs is coordinated vulnerability disclosure (CVD), in which firms publicly release vulnerability details after patching. Such disclosures can help hackers learn how firms evaluate reported vulnerability validity, thereby improving submission validity and reducing uncertainty about participation. However, because disclosed vulnerabilities are patched before release, they are no longer reproducible in the updated system, which limits their learning value. Furthermore, as disclosures accumulate, hackers may perceive the program as saturated, meaning that many accessible and reward eligible vulnerabilities appear to have already been discovered and patched, reducing perceived opportunities for further valid discoveries. These competing forces create tension in how vulnerability disclosure influences hacker behavior and bug bounty effectiveness, yet little empirical research has examined this relationship. Using data from a leading bug bounty platform, we examine how vulnerability disclosure affects submissions along both the volume and validity dimensions. We find that disclosure increases submission validity but reduces submission volume. Moreover, the decline in volume is strongest when disclosures involve the same system component repeatedly, common weakness types, and many vulnerabilities that are confirmed as valid. This pattern suggests that disclosure generates a saturation signal when previously rewarded discovery paths are perceived as exhausted. We further show that learning depends on the informational content of disclosed reports. Disclosing valid vulnerabilities benefits both new and experienced hackers, whereas disclosing invalid vulnerabilities primarily benefits newcomers who have no prior knowledge about the focal firms. Together, these findings highlight the dual role of vulnerability disclosure in bug bounty platforms and its implications for program effectiveness.
Suggested Citation: Suggested Citation