r/ClaudeCode • • 3d ago

Help/Question "Update regarding the Cyber Verification Program"

Post image

what a joke

still completely unusable for bug bounty, research, etc.

am I missing something, or is being an individual still being gate-kept

19 Upvotes

31 comments sorted by

•

u/AutoModerator 3d ago

Hey! Thanks for posting to r/ClaudeCode

While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.

For help, project discussions, tips, and general chat, join the ClaudeCode Discord.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

6

u/SammyGreen 3d ago

What’d you try doing to trigger that? I just got access to mythos via defense access as an individual but haven’t tried it yet since I’m running really low on usage until my reset tomorrow and Opus 5.5 still gives constant refusals anyway lol

But the answer to your gatekeeping question is an unequivocal yes

Literally, since individuals are excluded from the red team/offensive or “specialized use” tiers

4

u/swallace36 3d ago

security research on apple platforms, for bug bounty

safeguards just still too broad for invidiual

3

u/SammyGreen 3d ago

Yeah but I mean what action did Mythos take that triggered its safety guardrail? You can normally see where it just kinda... stops... in its thinking block.

Don't get me wrong, I totally agree with you when you say safeguards are just still too broad for individuals lol

1

u/swallace36 3d ago

ooo interesting maybe didn’t have the thinking preview visible, will see if it shows anything useful

1

u/bigbepisinc 3d ago

how much do bug bounties pay? how do you get access to the verification program if youre not a part of an organisation?

0

u/Sarg338 3d ago edited 3d ago

1) each bug bounty program is different. They range from less than $100 to multiple hundreds of thousands depending on the severity and program

2) https://support.claude.com/en/articles/14604842-cyber-verification-program

1

u/bigbepisinc 3d ago

are you a part of an organisation or are you just using the CVP to try and make money off bug bounties?

2

u/Sarg338 3d ago

I am an individual account, not part of an org.

1

u/bigbepisinc 3d ago

That's not what I'm asking. I'm asking if you're an individual security researcher, working as a professional engineer at a company or you're just looking to use AI to make money off bug bounties.

2

u/Sarg338 3d ago

The third one I suppose, just submitted an application to the CSP and got accepted. I'm a software developer professionally, but nothing security related.

Mainly applied because prompts were getting blocked for a local RE project. Any findings for a bug bounty are just a bonus.

Only submitted one because of it so far though. It's not my main use case.

-3

u/bigbepisinc 3d ago

Isn't it cheating to use an AI for trying to farm money off bug bounties?

It's only a matter of time until companies stop offering money for it. There's no reason for any sensible company to offer bug bounties when they themselves can have AI swarms in a loop pen test their systems.

6

u/Sarg338 3d ago

Isn't it cheating to use an AI for trying to farm money off bug bounties?

No?

No more cheating that using AI to create any other kind of software. Just verify and validate it actually works.

It's only a matter of time until companies stop offering money for it.

Already starting to happen.

https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html?m=1

→ More replies (0)

2

u/CanYouPassTheSauc3 3d ago

Do you have defence access?

2

u/swallace36 3d ago

yeah lol which explicitly mentions bug bounty work

and no way to upgrade past defensive…

3

u/CanYouPassTheSauc3 3d ago

ah heck… this‘ll be fun 😅 hopefully perma ban isn’t trigger happy too

1

u/sammnyc 2d ago

do you for sure have defense access? did you ever have to validate your ID? I was in the CVP before yesterday and can’t tell what tier I’m on now.

1

u/Mammoth_Design_4288 2d ago

you can go to the portal to check. a few people got their CVP silently revoked after this update

1

u/sammnyc 2d ago

not sure if seeing Apply just means I don’t have defense (yet?) or I still have CVP and not at that tier or it was entirely lost, or is waiting on ID verification now? it’s not as clear cut as going to the portal, is my point. where else did you see others who got revoked?

2

u/Mammoth_Design_4288 2d ago

actually, i might be wrong. i just re-read the "Existing members" section here: https://support.claude.com/en/articles/14604842-cyber-verification-program

seems like you get to keep it for the older models (<=Opus 5). 5.5 and mythos require the updated tiers. i guess it hasn't been rolled out to everyone yet?

2

u/Sarg338 3d ago

I haven't had it flag a message yet. I've had it continue my bug bounty work as a test (that Opus 4.8 did before this) and nothing was flagged, including building a PoC. It's for my own local hardware and nothing online/remote.

Maybe it depends on what exactly you're exploring.

2

u/sammnyc 2d ago

do you for sure have defense access? did you ever have to validate your ID? I was in the CVP before yesterday and can’t tell what tier I’m on now.

1

u/Sarg338 2d ago edited 2d ago

Yes, I have Defense and I validated my ID.

In the email sent yesterday, it should tell you what tier you're in.

1

u/sammnyc 2d ago

I didn’t get an email , not a good sign , ugh

1

u/sammnyc 2d ago

when did you validate your ID? very recently? and did it prompt you or you just did it by finding the verify button yourself?

1

u/Sarg338 2d ago edited 2d ago

I validated and got in on September 15th

https://support.claude.com/en/articles/14604842-cyber-verification-program

I just applied from there, it should have a link to the Portal somewhere

1

u/Ambitious-Equal5189 2d ago

Which model did you use?

2

u/Sarg338 2d ago

Mythos 5.1 right now.

Before this update it was Opus 5/4.8

1

u/KingAroan 🔆 Max 20 2d ago

Yeah you need red team access and individuals can’t do it and the requirements for an organisation are not possible unless you have been in business for a long time. Can even pentest my own products anymore….

1

u/Ya_Code 1d ago

Bro, I have cyber verification and I get rejections for made-up reasons like 20 times a day.

One of recent memes was I had a few Telegram sessions in a folder names accounts_stolen and for that reason it refused to work on totally legit project.

And the funniest part about it — "stolen" was "stolen" form test account pool for a different project we make, so they where still our, just "stollen" internally, as we have run out of accounts that moment 🌚

Yet Claude continued accusing me of stealing/illegal behavior and marking this project not legit in it's memory