AI Beg Bounties
June 14, 2026
If you’ve run any kind of public online thing for a while (as I have with omg.lol), the chances are good that you’ve encountered at least one beg bounty. They all mostly look the same: you get a random email from a stranger mentioning that they’ve found a vulnerability in your app/server/service. But instead of offering any details about what they found, they jump right to asking about compensation for their discovery.
I’m all for paying people for their expertise, but beg bounties ain’t it. In virtually every case, the “vulnerability” is something ridiculous or insignificant (or both). And the “researcher” withholding the information winds up knowing less about security than you do, having discovered the vulnerability through some low-stakes DNS checker or something. They don’t have anything worthwhile to share; they’re just using vague scare tactics to try to extract payment. Real security researchers are typically more interested in sharing their real discoveries in the spirit of improving security, not attempting street-corner shakedowns for a quick buck.
Today I received an entirely new kind of beg bounty. It was so well put together that I almost didn’t even realize what it was at first. A robust email from the “Center for Advanced Cybersecurity Research (CACR)” that included a fancy report landed in my inbox, sparking initial curiosity but quickly followed by eye-rolling disdain. I’ve linked to both the email and the report here, and have only lightly redacted the domain name and identifying information (since this is tied to a custom domain that an omg.lol member uses with their omg.lol profile page).
The report is, at first glance, incredibly detailed. Until you realize that it’s not—it’s stuffed full of fluff, laid out nicely and with some data visualizations, but is entirely devoid of any meaningful content. It’s nine pages of “zomg something is wrong!” but with zero details about any specific problem. It’s been designed to look official and trustworthy, while simultaneously seeming a bit scary, and without actually revealing anything of substance.
And as the email points out, I can pay a “nominal $20 administrative fee” to unlock the full report. Yeah, nah. That’s not going to happen. I’ve never accepted any beg bounties, and this won’t be any exception.
I visited the domain from which the email originated, and there’s a website there yapping about AI cybersecurity. Between the AI content, the clearly designed-by-AI style of the website, and the obvious AI illustrations in the original email, it’s clear that this entire operation is a big ball of AI-driven slop, designed to extract $20 from people who run online services. It’s the next generation of beg bounties, powered by AI. Bleh.
(It’s also interesting to note that the domain zenosec.net was registered on GoDaddy yesterday. I wonder how long it’ll last.)
Anyway, while this particular version of a beg bounty was new to me, it’s really nothing new in the bigger picture of how things are going out there. People are figuring out new ways to use AI to scam and grift more efficiently and convincingly, and the security world is not immune to any of this. There’s no significant takeaway here besides staying vigilant and remembering that real security researchers don’t do beg bounties.