跳到主内容
@wquguru
精选70Michael Lynch(独立开发 · RSS)独立开发与小生意

AI 挖漏洞月入 1 万美元,但作者纠结该写书还是继续挖

Refactoring English: Month 17

原文
发到 X

New here?

Hi, I’m Michael. I’m a software developer and founder of small, indie tech businesses. I’m currently working on a book called Refactoring English: Effective Writing for Software Developers.

Every month, I publish a retrospective like this one to share how things are going with my book and my professional life overall.

Highlights

  • I’m torn between focusing on my book and pursuing security bug bounties.
  • I’m considering a course to teach what I’ve learned about using AI to find security vulnerabilities.

Goal grades

At the start of each month, I declare what I’d like to accomplish. Here’s how I did against those goals:

Finish writing Refactoring English

  • Result: I’ve still got about 1-2 weeks of writing left
  • Grade: C

I keep feeling like I’m close to done, but then I spend more time than I intend to on bug bounties.

Refactoring English metrics

MetricMarch 2026April 2026Change
Unique visitors6,9322,578-4,354 (-63%)
Revenue from pre-orders$725.80$587.73-$138.07 (-19%)
Total Revenue$725.80$587.73-$138.07 (-19%)

Revenue dropped for the book, as I haven’t done any marketing since March. Instead, I’ve been getting distracted by bug bounty hunting. I’m glad I’ve been able to skate by on past effort, but I see the numbers trending toward zero if I neglect marketing.

Three months of bug bounty programs

For the past three months, I’ve been spending a lot of time using AI to find security vulnerabilities. I haven’t talked about it publicly because I didn’t want to attract competition to the limited supply of bug bounty programs. I wasn’t sure if other people realized just how effective AI is at security research, but I think the cat is out of the bag.

If you haven’t been following along with AI and security research, Firefox is an astonishing case study. Throughout 2025 (before AI was any good at security research) Mozilla and external researchers collectively found 10-20 security vulnerabilities in Firefox each month.

In February 2026, Anthropic used Claude Opus to find 22 Firefox vulnerabilities. In other words, that month, Anthropic alone found more than everyone else combined in any of the previous 13 months. Two months later, Anthropic used Claude Mythos to find a whopping 271 more vulnerabilities in Firefox.

I sort of spotted this early, but I got it slightly wrong. Back in January, I thought that AI might be able to revolutionize cybersecurity research, but I thought the value was in creating security tools. I was using AI to write fuzz testing tools and was amazed at how much faster I could perform fuzz testing than when I did it by hand.

Despite the fact that I could write fuzzers 10-20x faster, it turned out that my strategy was way more work than was necessary. Instead of asking AI to create a fuzz testing tool and evaluate its output, you can just ask AI, “Hey, look at the source code and tell me all the vulnerabilities.”

After I saw how good AI was at directly auditing source code, I stopped fuzzing and focused on source auditing. I’ve now reported 50+ bugs to five different bug bounty programs and earned about $10k in bug bounties.

The bugs have gotten easier to find, but the bounty programs have gotten harder

While I’ve successfully used AI to find security vulnerabilities, I’ve been less successful at finding companies willing to pay me for my findings.

Here are my results so far:

  • Vendor 1: Meta
  • I submitted eight reports, including one remote code execution bug.
  • I received no response for several weeks.
  • I found email addresses for developers that worked on the product and pinged them, and they escalated my reports to get them past triage, but there’s been no movement since then (two weeks and counting).
  • Vendor 2
  • I submitted one report.
  • Vendor triaged it in one business day, but said it would be several weeks before they could investigate thoroughly.
  • I haven’t heard anything in over 30 days.
  • Vendor 3:
  • I submitted one report.
  • Vendor claimed it was a duplicate, so no bounty.
  • Vendor 4
  • I’ve submitted 40ish reports.
  • Eight were paid after two weeks for a total of $9,700.
  • Two were rejected as duplicates.
  • The remaining are all awaiting triage, though the most valuable ones were in the first eight that have received payouts.
  • Vendor 5: Firedancer (crypto project)
  • Found a few medium-severity issues.
  • When I started the bounty reporting process, I realized that they require researchers to upload their passport to a service I’ve never heard of, so I stopped there.
  • Their program rules are also sketchy in that they seem to contradict the rules of the bounty platform they’re using.

So, the $10k from vendor 4 only took two weeks of part-time work. That would be a great return on investment had I not also spent 6+ weeks on bounty programs that paid nothing. It would also be great if I could find more vendors like vendor 4, but I don’t know how to do that.

Should I focus on the book or bug bounties?

I’m now torn on how to allocate my time between the book and bug bounties. Here’s my thinking:

  • Focus on my book
  • Pro: The book is nearly done, so if I focus on finishing, it will be complete and more valuable than a partially-finished book.
  • Pro: The book is something only I can create, whereas lots of people can participate in bug bounties.
  • Pro: I’m already late on delivering the book, so finishing it makes me feel less guilty about making readers wait.
  • Pro: I can talk publicly about my book, and not only does it help me think out loud, it helps new readers discover the book.
  • Con: The expected value of the book feels lower than bounty hunting, at least in the short-term. In theory, I could find a $100k bug next week, whereas it’s unlikely I could do anything that would drive $100k in book sales by next week.
  • Focus on bug bounties
  • Pro: I made more in two weeks of bug bounties than I did in all of 2025 on my book.
  • Pro: There’s still a massive amount of undiscovered, bounty-paying bugs that AI tools can find.
  • Pro: If I pause for a few months, the value of the remaining bugs will be significantly lower, as many other researchers will have claimed the easy-to-find bugs.
  • Con: Participating in bug bounties is frustrating, as you have no leverage. The vendor can completely lowball or shaft you, and you have no recourse or negotiating power unless you sell the exploit to buyers who want to use it for nefarious purposes.
  • Con: Bug bounty hunting is addictive like gambling in that there are variable rewards that appear semi-randomly.
  • Con: Bug bounties push me back into bad AI usage habits. If I have an AI agent searching for bugs in the background, I constantly want to check on its progress and redirect it based on early results.
  • Con: I’m much more limited in what I can share publicly about my work, both because bounty programs often require it and because I don’t want to attract competition to the same places where I’m focusing effort.

Rationally, I have a hard time justifying why I should continue chasing bug bounties, but I do want to keep at it a little bit, maybe like a 70/30 split between the book and bug bounties.

Maybe I should be teaching AI for improving software security

A third possibility is that instead of chasing bug bounties, I teach people what I’ve learned in the last few months about using AI to find security vulnerabilities.

I’m thinking about offering a small, cohort-based course where we find bugs in open-source projects. We’ll pick projects with no bug bounty attached so that students can internally share findings without worrying about someone running off with their reward. The format will be some combination of live or recorded screencasts + a private group chat for 2-4 weeks.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近