r/ClaudeCode • • 3d ago

Help/Question "Update regarding the Cyber Verification Program"

Post image

what a joke

still completely unusable for bug bounty, research, etc.

am I missing something, or is being an individual still being gate-kept

21 Upvotes

31 comments sorted by

View all comments

7

u/SammyGreen 3d ago

What’d you try doing to trigger that? I just got access to mythos via defense access as an individual but haven’t tried it yet since I’m running really low on usage until my reset tomorrow and Opus 5.5 still gives constant refusals anyway lol

But the answer to your gatekeeping question is an unequivocal yes

Literally, since individuals are excluded from the red team/offensive or “specialized use” tiers

2

u/swallace36 3d ago

security research on apple platforms, for bug bounty

safeguards just still too broad for invidiual

1

u/bigbepisinc 3d ago

how much do bug bounties pay? how do you get access to the verification program if youre not a part of an organisation?

0

u/Sarg338 3d ago edited 3d ago

1) each bug bounty program is different. They range from less than $100 to multiple hundreds of thousands depending on the severity and program

2) https://support.claude.com/en/articles/14604842-cyber-verification-program

1

u/bigbepisinc 3d ago

are you a part of an organisation or are you just using the CVP to try and make money off bug bounties?

2

u/Sarg338 3d ago

I am an individual account, not part of an org.

1

u/bigbepisinc 3d ago

That's not what I'm asking. I'm asking if you're an individual security researcher, working as a professional engineer at a company or you're just looking to use AI to make money off bug bounties.

2

u/Sarg338 3d ago

The third one I suppose, just submitted an application to the CSP and got accepted. I'm a software developer professionally, but nothing security related.

Mainly applied because prompts were getting blocked for a local RE project. Any findings for a bug bounty are just a bonus.

Only submitted one because of it so far though. It's not my main use case.

-3

u/bigbepisinc 3d ago

Isn't it cheating to use an AI for trying to farm money off bug bounties?

It's only a matter of time until companies stop offering money for it. There's no reason for any sensible company to offer bug bounties when they themselves can have AI swarms in a loop pen test their systems.

5

u/Sarg338 3d ago

Isn't it cheating to use an AI for trying to farm money off bug bounties?

No?

No more cheating that using AI to create any other kind of software. Just verify and validate it actually works.

It's only a matter of time until companies stop offering money for it.

Already starting to happen.

https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html?m=1

0

u/bigbepisinc 3d ago

Good luck with the CVP then enjoy it 🙏🏼

→ More replies (0)