Vulnerability Disclosure as a Signal: Effects on Submission Volume and Validity in Bug Bounty Programs

Posted: 30 Jul 2024 Last revised: 19 Feb 2026

See all articles by Ali Ahmed

Ali Ahmed

Louisiana State University, Baton Rouge

Ho Cheung Brian Lee

Department of Supply Chain & Information Systems

Amit V. Deokar

University of Massachusetts Lowell - The Robert J. Manning School of Business

Date Written: February 18, 2026

Abstract

As cyberattacks pose increasing financial risks, organizations are turning to bug bounty programs to crowdsource vulnerability discovery. However, program effectiveness is often weakened by hackers’ uncertainty about firms’ internal criteria for judging a reported vulnerability’s validity, that is, whether it creates a meaningful security risk in the firm’s specific context and qualifies for a reward. A key feature of these programs is coordinated vulnerability disclosure (CVD), in which firms publicly release vulnerability details after patching. Such disclosures can help hackers learn how firms evaluate reported vulnerability validity, thereby improving submission validity and reducing uncertainty about participation. However, because disclosed vulnerabilities are patched before release, they are no longer reproducible in the updated system, which limits their learning value. Furthermore, as disclosures accumulate, hackers may perceive the program as saturated, meaning that many accessible and reward eligible vulnerabilities appear to have already been discovered and patched, reducing perceived opportunities for further valid discoveries. These competing forces create tension in how vulnerability disclosure influences hacker behavior and bug bounty effectiveness, yet little empirical research has examined this relationship. Using data from a leading bug bounty platform, we examine how vulnerability disclosure affects submissions along both the volume and validity dimensions. We find that disclosure increases submission validity but reduces submission volume. Moreover, the decline in volume is strongest when disclosures involve the same system component repeatedly, common weakness types, and many vulnerabilities that are confirmed as valid. This pattern suggests that disclosure generates a saturation signal when previously rewarded discovery paths are perceived as exhausted. We further show that learning depends on the informational content of disclosed reports. Disclosing valid vulnerabilities benefits both new and experienced hackers, whereas disclosing invalid vulnerabilities primarily benefits newcomers who have no prior knowledge about the focal firms. Together, these findings highlight the dual role of vulnerability disclosure in bug bounty platforms and its implications for program effectiveness.

Suggested Citation

Ahmed, Ali and Lee, Ho Cheung Brian and Deokar, Amit, Vulnerability Disclosure as a Signal: Effects on Submission Volume and Validity in Bug Bounty Programs (February 18, 2026). Available at SSRN: https://ssrn.com/abstract=4880721

Ali Ahmed

Louisiana State University, Baton Rouge ( email )

Baton Rouge, LA 70803
United States

Ho Cheung Brian Lee (Contact Author)

Pennsylvania State University - Department of Supply Chain & Information Systems ( email )

Dept. of Supply Chain & Information Systems
University Park, PA 16802-3306
United States

Amit Deokar

University of Massachusetts Lowell - The Robert J. Manning School of Business ( email )

1 University Ave
Pulichino Tong Business Center 436
Lowell, MA 01854
United States
9789345524 (Phone)

HOME PAGE: http://www.uml.edu/MSB/faculty/Deokar-Amit.aspx

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Abstract Views
639
PlumX Metrics