Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
    1
    Critical Thinking - Bug Bounty Podcast

    Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

    7/23/20261:13:10
    0:001:13:10

    The episode in 30 seconds

    This episode dives into the world of AI-assisted bug bounty hunting, featuring a guest who submitted 728 vulnerabilities in six months using open-source models, achieving high ROI without subsidized tokens. The discussion covers the shrinking gap between expert and off-the-shelf tools, noise reduction techniques like modular skills and reflection models, and Meta's FBDL tool that boosts bounties by 20%. The addictive, gambling-like nature of bug hunting is explored, highlighting risks of burnout. Practical strategies for targeting high-value programs and automating the research and reporting cycle are shared.

    Rate this episode

    Share this episode

    0D
    Critical Thinking - Bug Bounty Podcast

    0xMoose (Ads Dawson) on Critical Thinking - Bug Bounty Podcast

    Key takeaways

    Artificial IntelligenceStartups

    A bug bounty hunter using open-source and smaller AI models submitted 728 vulnerabilities in six months, achieving a high ROI despite paying full token costs, contrasting with most hunters relying on subsidized Frontier models.

    Artificial IntelligenceCybersecurity

    AI-powered bug hunting agents are becoming more efficient by using modular skills and reflection models to reduce noise and improve vulnerability detection, with tools like FBDL from Meta enabling automated test data provisioning and boosting bounties by 20%.

    StartupsPsychology

    Bug bounty hunting can be as addictive as gambling, driven by the dopamine rush from finding bugs, earning bounties, and receiving new targets, which can lead to burnout.

    Episode claims, checked

    Automatically checked with AI. Verify important claims against the linked sources.

    Disputed

    He submitted 728 vulnerabilities in 2026, and we're only halfway through 2026.

    As of now, the current year is 2025, not 2026, making this statement factually inaccurate.

    Needs context

    GLM 5.2 is as good as something like Opus 4.6 or 4.7.

    No known model named GLM 5.2 or Opus 4.6/4.7 exists in well-established sources; these appear speculative.

    Disputed

    Claude Code is $200 a month.

    Claude Code (likely referring to Anthropic's Claude Pro) is $20/month, not $200; there is no widely known plan at $200/month.

    Anthropic
    Verified

    Meta's bug bounty program offers a 20% bonus up to $500 for using FBDL in reports.

    This matches publicly known Meta Bug Bounty bonus programs for using FBDL to improve reproducibility.

    Needs context

    Between 2025 and 2026, noise and severity ceiling dropped from 32% to 24% due to modularity and flexibility of skills.

    The specific figures lack public corroboration and the timeline is future relative to the podcast date, making it speculative.

    Needs context

    Ads has made 853+ submissions with help of his hackbot, reaching 6x of his total full year for 2025.

    The numbers are plausible but not verifiable; 2025 is not yet complete, so 'full year' is speculative.

    Chapters

    Jump to a moment

    This Week in Bug Bounty and Vulnerability Vibes party
    Messi and Lamine Yamal photo coincidence
    CSS injection bug shared by Ads Dawson
    Hackbot performance: 728 submissions and model choices
    Tech Debt Debate and Open Source Model Capabilities
    Durable Advantage and Researcher-Builder Loop
    AI-Assisted Reporting and Verifier Design
    FBDL: Meta's Terraform-like tool for bug bounty automation
    Reducing noise in AI hacking: skills, reflection, and hill climbing
    Agent observers and per-program reflection logs
    The addictive nature of bug bounty

    Full transcript

    Ratings & reviews

    No ratings yet

    Discussion

    0 comments · timestamp your take

    Thomas Wolf
    Thomas Wolf
    @thom_wolf

    Co-founder at @HuggingFace - moonshots - angel

    14 want this
    Jobert Abma
    Jobert Abma
    @jobertabma

    I tweet about security and my experience as a hacker. Co-founder of HackerOne (@Hacker0x01).

    1 want this