← the record
AIAAIC-1210

Immunefi bans 'inaccurate' ChatGPT-generated bug bounty reports

C rypto bug bounty platform Immunefi banned 15 users from submitting reports generated by ChatGPT after they were found to be 'inaccurate' and 'irrelevant'. Shortly after ChatGPT was released, Immunefi started receiving 'a flood' of bug reports, many of which were 'nonsensical' and amounted to little more than spam. The finding persuaded the company to ban ChatGPT-generated reports. Immunefi later published (pdf) a report that found that 76 percent of so-called white hat researchers use ChatGPT as part of their everyday workflow, with 64% saying the chatbot provided 'limited accuracy' in identifying security vulnerabilities. The company said ChatGPT-generated reports accounted for 21 percent of accounts banned, though not a single genuine vulnerability had been discovered using the chatbot. S ystem 🤖 ChatGPT Operator: Developer: OpenAI Country: USA Sector: Technology Purpose: Generate text Technology: Chatbot; Generative AI; Machine learning Issue: Accuracy/reliability; Security

Date it happened
2023-01-01
Product, system or model
ChatGPT
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.