Nextcloud ends bug bounty program due to too many low-quality reports

TL;DR AI
2 min readKey summary
Nextcloud is ending cash rewards in its HackerOne bug bounty program.
The company says it has been flooded with generic, low-quality, and often AI-generated security reports.
Valid vulnerability disclosures will still be accepted, but no rewards will be paid for new submissions after April 22.
The move highlights how AI-generated low-signal reports can overwhelm vulnerability disclosure programs.



