Loading prices…
STKR NewsSTKR News0 of 3 free this month
AI

Apple's AI Slop Problem Left a $200K macOS Exploit Unreported

A Milanese startup discovered a full-takeover macOS exploit using ChatGPT, but Apple's new AI-driven submission caps prevented them from reporting it, leaving a massive security hole open.

Originally on Decrypt
AB

Adrian Boysel

Contributor

Aug 4, 2026

4 min read

Photo illustration / STKR News

Security researchers in Milan just highlighted a glaring friction point between legacy big tech and the new reality of AI-assisted development. While trying to report a critical vulnerability that would allow a total takeover of macOS, a startup called Shielder hit a brick wall. The wall wasn't a technical patch or a complex firewall; it was a submission cap on Apple's bug bounty portal.

The Velocity Problem

In the old world of security research, finding a zero-day exploit was a manual, grueling process. You sat in a dark room, pored over thousands of lines of code, and maybe found a needle in the haystack once every few months. Apple built its security intake systems for that world. They expected a slow, steady drip of high-quality reports from a handful of elite researchers.

Then came Large Language Models. Shielder researchers didn't just stumble onto this $200,000-tier exploit; they used ChatGPT to help sift through the noise and identify patterns that lead to a full system compromise. AI has effectively turned the manual needle-search into a high-speed magnet. The result is a flood of reports, some brilliant and some, as Apple calls it, slop.

Apple’s response to this influx was to throttle everyone. By implementing a cap on how many bugs a researcher can submit, they’ve accidentally created a situation where a critical, system-level exploit is sitting in a queue because the researcher already reported too many minor bugs earlier in the month. This isn't just a bureaucratic annoyance; it’s a massive security risk for every Mac user.

Builders vs. Gatekeepers

For those of us building in the crypto and AI space, this story feels all too familiar. We are moving at a speed that traditional institutions simply cannot handle. Apple is trying to maintain a curated, boutique experience for its security researchers while the tools of the trade have gone industrial. It is the classic struggle between the agile builder and the rigid gatekeeper.

The irony here is that Apple is betting its entire future on Apple Intelligence. They are integrating AI into every corner of the operating system, yet their internal infrastructure for handling the output of that same technology is failing. They are essentially inviting the world to use AI to find holes in their software, then closing the door when people actually find them.

The AI Slop Dilemma

To be fair to Apple, the "slop" problem is real. Since the barrier to entry for security research has dropped, bounty programs are being buried under thousands of AI-generated reports that make no sense or report non-existent issues. It is the same problem we see in content creation and software development: AI makes it easier to produce, but it doesn't necessarily make it easier to produce something good.

However, throttling is a lazy solution. It assumes that volume is inversely proportional to quality. In Shielder's case, they had a legitimate, high-impact exploit that remained unreported because the system couldn't distinguish between a script kiddie using ChatGPT to spam the portal and a professional firm using AI to enhance their workflow.

The friction between AI-accelerated research and human-paced review systems is going to be the primary cause of major exploits in the next twenty-four months.

What This Means for Crypto Founders

If you are building a decentralized protocol or a new AI layer, you need to learn from Apple’s mistake. You cannot rely on legacy bounty structures. If your project is open source, the speed at which vulnerabilities will be found is going to triple. If your intake process involves a manual review team that gets overwhelmed by ten reports a day, you are going to get crushed.

  • Automate the triaging: Use AI to fight AI. If you are getting flooded with reports, build a classifier to filter out the low-hanging fruit or the hallucinations.
  • Dynamic Caps: Don't use a hard cap like Apple. Use a reputation-based system. If a researcher has a history of high-value finds, their limits should be nonexistent.
  • Transparency: Shielder went public because they were frustrated. If you don't provide a clear path for disclosure, researchers will take their findings to the dark web or the public square.

The Real Cost of Friction

Apple’s $200,000 bounty is a drop in the bucket for a company with their balance sheet. The real cost isn't the payout; it’s the reputational damage and the risk to the user base. By making it difficult to report a full-takeover exploit, they have effectively signaled to the research community that their time isn't valued.

In the crypto world, we call this a lack of alignment. The incentives for the researcher (finding bugs and getting paid) are now at odds with the incentives of the gatekeeper (reducing noise and managing overhead). When incentives misalign, the system breaks. In this case, the break is a macOS exploit that could have been patched weeks ago but instead sat on a hard drive in Milan because a web form said "Too many requests."

Takeaway

The era of the "polite researcher" who waits for a response is over. AI has accelerated the discovery of flaws to a point where traditional security models are obsolete. If you are building high-stakes software, your security intake must be as fast and as scalable as the tools being used to break it. If you build a bottleneck, don't be surprised when the water starts leaking elsewhere.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses