Apple Missed a $200K macOS Flaw Because Their Anti-AI Spam Gate Shut Out Real Researchers
A Milan startup found a critical macOS exploit using ChatGPT, but couldn't report the $200,000 bug after crashing into Apple's blunt submission limits.
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
Key takeaways
- A Milan startup used ChatGPT to find a full-takeover flaw in macOS.
- Apple introduced submission caps to filter out AI-generated spam reports.
- The startup hit the new cap before filing the $200,000 exploit report.
- AI-generated bug spam is overwhelming security teams and blocking real disclosures.
A startup out of Milan used ChatGPT to dig up a full-takeover vulnerability hiding inside macOS. But when the researchers tried handing Apple their $200,000 discovery, they slammed right into a brick wall.
Apple recently capped bug bounty submissions to stop a tidal wave of garbage, AI-generated reports flooding its portal. That anti-spam wall backfired fast—the Italian team hit the submission ceiling before they could even submit their legitimate exploit.
Drowning in AI Slop
Large language models give security teams a fast way to audit complex code bases. But here's the catch. Low-effort hackers and spammers use those exact same AI tools to churn out endless hallucinated bug reports, drowning bounty programs in pure noise.
Tech firms locked down intake forms so their engineers stop wasting time on low-grade junk. Too bad hard caps are a blunt filter. When real researchers uncover critical zero-day flaws, they get thrown into the spam bucket and turned away.
Why it matters
If you use a Mac to manage crypto wallets, sign transactions, or store private keys, OS-level security flaws are a massive threat. A full-takeover bug gives remote attackers direct entry to your local files, clipboard data, and keychains.
When legitimate security reports get blocked by AI noise, crucial patches stall out. That leaves everyday crypto holders stuck relying on vulnerable software while vendor intake desks try sorting through the trash.
Source: Decrypt
Top Crypto Casinos Right Now
🇺🇸 Showing sites that accept players from United States Change country
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
More info Less info
Why we chose it: Thirty years of paying people, no ownership shuffles, no mass-confiscation scandal. You trade crypto choice and a modern interface for that.
- Online since
- 2011
- Licence
- Curaçao
- Min deposit
- $25
- Payout time
- 1–24 hours (crypto)
- KYC
- Required
Restricted countries: Australia, Austria, Germany, United Kingdom, France, Slovakia.
More info Less info
Why we chose it: The casino wing of a bookmaker that has paid people since 1996, and one of the few crypto-friendly casinos still open to Americans.
- Online since
- 2011
- Licence
- Curaçao
- Min deposit
- $25
- Payout time
- 1–24 hours (crypto)
- KYC
- Required
Restricted countries: Australia, Austria, Germany, United Kingdom, France, Slovakia.
More info Less info
Why we chose it: A poker room that still seats Americans, backed by the widest crypto cashier of the US-facing sites — 17 coins in and out, with casino and sports on the same balance.
- Online since
- 2004
- Min deposit
- $10
- Payout time
- Within 24 hours (crypto)
- KYC
- Required
Restricted countries: Australia, United Kingdom, France, Malta, Slovenia, Panama, North Korea, Iran and 19 more.
Sofia Marek
Sofia reviews exchanges and crypto casinos, focused on fees, safety and what actually reaches the player.