Apple Missed a $200K macOS Flaw Because Their Anti-AI Spam Gate Shut Out Real Researchers
A Milan startup found a critical macOS exploit using ChatGPT, but couldn't report the $200,000 bug after crashing into Apple's blunt submission limits.
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
Key takeaways
- A Milan startup used ChatGPT to find a full-takeover flaw in macOS.
- Apple introduced submission caps to filter out AI-generated spam reports.
- The startup hit the new cap before filing the $200,000 exploit report.
- AI-generated bug spam is overwhelming security teams and blocking real disclosures.
A startup out of Milan used ChatGPT to dig up a full-takeover vulnerability hiding inside macOS. But when the researchers tried handing Apple their $200,000 discovery, they slammed right into a brick wall.
Apple recently capped bug bounty submissions to stop a tidal wave of garbage, AI-generated reports flooding its portal. That anti-spam wall backfired fast—the Italian team hit the submission ceiling before they could even submit their legitimate exploit.
Drowning in AI Slop
Large language models give security teams a fast way to audit complex code bases. But here's the catch. Low-effort hackers and spammers use those exact same AI tools to churn out endless hallucinated bug reports, drowning bounty programs in pure noise.
Tech firms locked down intake forms so their engineers stop wasting time on low-grade junk. Too bad hard caps are a blunt filter. When real researchers uncover critical zero-day flaws, they get thrown into the spam bucket and turned away.
Why it matters
If you use a Mac to manage crypto wallets, sign transactions, or store private keys, OS-level security flaws are a massive threat. A full-takeover bug gives remote attackers direct entry to your local files, clipboard data, and keychains.
When legitimate security reports get blocked by AI noise, crucial patches stall out. That leaves everyday crypto holders stuck relying on vulnerable software while vendor intake desks try sorting through the trash.
Source: Decrypt
Top Crypto Casinos Right Now
🇺🇸 Showing sites that accept players from United States Change country
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
More info Less info
Why we chose it: A US-facing book that pays a premium for crypto deposits: 125% against 100% for cash, with fee-free deposits across five coins.
- KYC
- Required
Restricted countries: Australia, Afghanistan, Bulgaria, Central African Republic, Congo - Brazzaville, Eritrea, France, Guinea-Bissau and 16 more.
More info Less info
Why we chose it: BetNow's casino floor with the biggest match bonus we list. The 200% headline deserves a careful read of the code terms behind it.
- KYC
- Required
Restricted countries: Australia, Afghanistan, Bulgaria, Central African Republic, Congo - Brazzaville, Eritrea, France, Guinea-Bissau and 16 more.
More info Less info
Why we chose it: A US-oriented casino that turns away only New Jersey. The cashier takes crypto, but the site publishes fewer specifics than any operator we list.
- KYC
- Required
Restricted countries: New Jersey (US).
Sofia Marek
Sofia reviews exchanges and crypto casinos, focused on fees, safety and what actually reaches the player.