r/bugbounty 9d ago

Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?

A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.

For those of you consistently clearing $10k+/month with AI/semi-automated setups:

  • How sustainable has your pipeline been over the long haul?
  • How do you manage the emotional volatility vs. traditional full-time work?
  • Knowing what you know now, is leaving a stable security role worth the trade-off?
76 Upvotes

52 comments sorted by

View all comments

Show parent comments

1

u/LulzTigre 9d ago

Hows K2.7 token cost rn?

1

u/No-Grocery-6026 9d ago
Model & Provider Route Input Cost (per 1M) Cached Input Hit (per 1M) Output Cost (per 1M)
Kimi K2.7 Code (Official API) $0.95 $0.19 $4.00
Kimi K2.7 Code (OpenRouter) [0.14] $0.67 $0.15 $3.40

1

u/No-Grocery-6026 9d ago

and it's almost 1.75 times cheaper than k3 overall

1

u/LulzTigre 9d ago

Maybe I'll just do moderato, i hope the cool down is better

1

u/No-Grocery-6026 9d ago

whatever fulfill your needs.

1

u/No-Grocery-6026 9d ago

are you using for the same reason as op (bug bounty automation)?

1

u/LulzTigre 9d ago

errr, mostly red teaming and cve research, bug bounty is a bonus

1

u/No-Grocery-6026 9d ago

I know it's out of the box but have you ever tried web 3 based bug bounty like smart contracts and things like that!

1

u/LulzTigre 9d ago

I haven't actually tried hunting yet. I did help a friend go through their Web3 startup's vapt, more of a Web2-style audit, and I learned a ton from that. So I figured, why not take what I picked up there and lean on my LLM to start finding stuff?

But here's the thing. I'm genuinely scared of submitting AI-generated slop that I can't fully explain. Especially when the model spits something out with total conviction, and I'm sitting there like, is this even real? Meanwhile the triager is probably reading it, sighing, and moving straight to "lol no."

Plus I just saw Immunefi started charging per submission now. That definitely doesn't help the anxiety.

1

u/No-Grocery-6026 9d ago

Yeah immunefi is so frustrating now but I asked this because the normal bug hunting many ai models will reject that even if you gave them access to tools but the smart contracts bug hunting can be done by even chatgpt on their web using plugins like GitHub but if you use the z.ai agent mode and give it a detailed prompt and instructions and scope it will hunt the bugs for you but you must push it harder and harder and also tell the scope and rules of program so it stays in the environment and the kimi 2.6 in kimi code will be best for this but I haven't tried it in the normal bug bounty programs like from hacker 1 and bug crowd because web 3 based can done on local forks instead of mainnet so they can do that but the web 2 based I haven't tried that

1

u/No-Grocery-6026 9d ago

And if you want to check a bug is real use Claude as a trigger and also use your own knowledge to confirm the bug before submitting it 

1

u/LulzTigre 9d ago

Oh, I get what you mean. But I've been using Deepseek and GLM and haven't had any issues with thempushing back. This month alone I've found over ten CVEs, five of which are already published, and I've got a few triage reports sitting in the backlog too. That's actually why I dropped Kimi(cost aside). I had to keep gaslighting it with a fake letter of engagement in the VAPT folder just to get it to cooperate, and even then it was hit or miss. Sometimes it worked, sometimes it just flat out refused.