An top-tier ethical hacker has warned that the competitive bug hunting era could be drawing to a close, as artificial intelligence tools develop the capability to outpace even the most skilled security professionals. Valentina Palmiotti, known professionally as Chompie, proved to be the most successful individual competitor at Pwn2Own Berlin, the globally renowned hacking competition, where she earned close to $70,000 in rewards by identifying critical vulnerabilities in major software systems. Yet despite her triumph, she voiced worry that sophisticated artificial intelligence systems—particularly Claude Mythos, created by Anthropic—will eventually prevent for security researchers to compete. “I participated in Pwn2Own this year because I felt it could be my final opportunity,” she informed BBC News, highlighting fears that AI-driven vulnerability discovery will fundamentally transform the landscape of ethical hacking and bug bounty programmes.
The Pwn2Own winner’s defining moment
Chompie’s leading position at Pwn2Own Berlin highlighted the exceptional skill required to succeed at the world’s most demanding hacking contest. On the opening day of the competition, she performed a advanced strike against an Nvidia-associated system, securing $20,000 for her work. Rather than become complacent, she straight away headed back to her lodgings to prepare for the subsequent round, entering what she describes as “zombie hacker mode”—an intense state of non-stop labour sustained by energy drinks and adrenaline that went on throughout the night.
The impact of this unrelenting effort became evident when video of the event showed Chompie on stage looking both exhilarated and drained after breaching a Linux-based system to obtain an additional $50,000 prize. She had worked from 6pm until 6am without sleep, a grueling 12-hour marathon that she admitted was far from ideal. Yet such commitment has become standard practice amongst leading competitors, who stretch themselves to the maximum of human endurance to secure victories at the esteemed annual tournament. Chompie’s total earnings of almost $70,000 reflected not just technical expertise but steadfast resolve.
- Infiltrated Nvidia-linked system for $20,000 on day one
- Worked continuously for twelve hours without sleep for the second try
- Successfully breached Linux system generating extra $50,000
- Described the intense competitive state as “zombie hacker” state
How machine learning is reshaping the security threat terrain
The adoption of artificial intelligence into cybersecurity has fundamentally altered how ethical hackers conduct their work. Tools like Claude Code have become invaluable assistants, enabling researchers to enhance their vulnerability discovery processes and refine their assessment approaches. For competitors like Chompie, these intelligent platforms have provided a strategic advantage during gruelling marathon sessions, enabling them to work more efficiently whilst preserving the intensity required to excel at premier-level contests. The technology has broadened access to certain aspects of security testing, making complex approaches more available to a wider spectrum of cybersecurity experts across the world.
However, this technological revolution has created a concerning contradiction. Whilst existing artificial intelligence systems function as helpful supplements to human expertise, increasingly sophisticated models threaten to render human competitors obsolete entirely. Anthropic’s Claude Mythos has already demonstrated the potential scale of this upheaval, reportedly identifying 1,600 security flaws throughout numerous software applications—a capacity that far exceeds what individual hackers can accomplish through traditional methods. The company has restricted access to governments and select cybersecurity institutions, acknowledging the dual-use implications of such powerful technology.
The existing advantage for human researchers
At the moment, ethical hackers occupy what Chompie describes as a “sweet spot” where artificial intelligence functions as an enabler rather than a replacement. Contemporary AI tools perform well in accelerating routine tasks, automating code analysis, and suggesting research directions that might otherwise necessitate hours of manual investigation. For security researchers working in high-pressure environments—whether competing at Pwn2Own or conducting vulnerability assessments for organisations like IBM X-Force—these tools have become vital efficiency enhancers. The human element remains central, requiring creativity, intuition, and strategic thinking that current AI systems cannot adequately reproduce.
This combined advantage has allowed champions to advance their operational boundaries to new heights. By offloading computational heavy lifting to artificial intelligence tools, leading penetration testers can focus their cognitive resources on complex problem-solving and emerging security vulnerabilities. The advancement has extended our capabilities rather than replaced it, creating a mutually beneficial partnership where both human and machine contributions remain critical for achieving objectives. Yet this equilibrium seems fleeting, with increasingly advanced systems already in development.
The forthcoming turning point
The cybersecurity community faces an imminent technological inflection point as advanced artificial intelligence models emerge. GPT 5.5 Cyber and similar systems offer capabilities that will substantially surpass human performance in identifying vulnerabilities. Unlike existing systems that augment human researchers, these sophisticated systems are built to function with limited human involvement, potentially identifying and exploiting security flaws at speeds and scales that humans cannot match. This shift represents a pivotal juncture for the hacking landscape, where conventional expertise may prove inadequate against artificial intelligence-powered methods.
Chompie’s decision to compete at Pwn2Own this year demonstrates a broader anxiety within the ethical hacking field about the future viability of human-led contests. As AI systems become increasingly advanced, the scope of human-dominated bug bounties and hacking competitions may rapidly close. The restriction of Claude Mythos to specific organisations emphasises how seriously security experts regard this risk, yet such restrictions offer only fleeting respite. The age of human-led bug bounties that has defined ethical hacking for decades appears ready for fundamental shift within the near future.
Contrasting viewpoints on the future of humanity in digital security
Whilst Chompie’s reservations about AI dominance reverberate within the ethical hacking community, not all IT security specialists share her pessimistic outlook. Some argue that human insight, originality and judgment will always hold fundamental worth in penetration testing. They point to the erratic character of cybersecurity threats and the value of contextual knowledge that machines struggle to replicate. These optimists propose that rather than displacing security researchers, advanced AI will remain advancing as a tool that elevates the entire profession, allowing researchers to tackle increasingly complex problems whilst upholding human supervision and moral boundaries.
The debate demonstrates a broader divide across cybersecurity about technical innovation and professional identity. Key figures in the sector accept that AI will inevitably transform bug bounty programmes and organised hacking challenges, but they stress that human skill stays irreplaceable in strategic decision-making and threat analysis. Organisations such as Anthropic have intentionally controlled access to advanced systems exactly because they recognise the potential hazards of unchecked AI-driven vulnerability detection. This cautious strategy points to the future may include integrated systems where people and artificial intelligence work together under strict governance, as opposed to total substitution of human hackers with self-governing systems.
- Human creativity crucial for new offensive approaches AI cannot anticipate
- AI governance with limited availability may preserve competitive opportunities
- Hybrid human-AI teams likely to define the future of cybersecurity
Implications for both defensive and offensive players
The growth of AI-powered flaw identification introduces a double-edged challenge for the cybersecurity landscape. Whilst ethical hackers and vulnerability experts have traditionally functioned as the primary defensive barrier, identifying flaws before malicious actors can leverage them, the democratisation of AI tools risks create parity. If advanced systems become widely accessible, cybercriminals could theoretically discover vulnerabilities at volume, potentially outpacing the ability of security teams to apply fixes. This imbalance could fundamentally alter the cost dynamics of cybersecurity, forcing organisations to allocate substantially greater resources in protective strategies and swift remediation capabilities to compensate for accelerated threat discovery.
Conversely, the identical AI capabilities could enhance defensive operations substantially. Security teams furnished with sophisticated AI technologies could theoretically identify and remediate vulnerabilities at unprecedented speeds, potentially keeping pace with threats. The essential element lies in access controls. If AI vulnerability discovery tools remain strictly limited to established security bodies and governments, as Anthropic currently ensures with Mythos, defenders may preserve their superiority. However, should such technologies ultimately be disclosed or be reverse-engineered, the consequences could be grave, making the question of responsible deployment and access controls paramount to cybersecurity’s ongoing resilience.
The criminal hacker landscape
The possibility of AI-assisted flaw identification in the hands of cybercriminals constitutes perhaps the most concerning scenario facing the security community. Malicious actors have repeatedly shown their ability to weaponise new technologies faster than defenders can respond. If criminal organisations gain access to models like Mythos, they could conduct automated searches for exploitable flaws across vast swathes of software and infrastructure, effectively industrialising the vulnerability discovery process. This would grant them unparalleled velocity and breadth in locating targets, potentially overwhelming the capacity of ethical hackers and defensive personnel to respond effectively.
Anthropic’s choice to restrict Mythos access demonstrates acute awareness of this danger. The company clearly recognised the model’s capacity for abuse, restricting access to chosen authorities and security organisations. This access control strategy, though contentious, represents a pragmatic recognition that unfettered AI access could empower criminal enterprises disproportionately. However, such restrictions may turn out to be short-lived. Evidence indicates that advanced systems eventually proliferate beyond their intended boundaries, raising uncomfortable questions about how long responsible deployment practices can contain instruments created expressly to uncover concealed vulnerabilities in digital infrastructure.
Responsible rollout as the key factor
The future direction of ethical hacking and cybersecurity depends significantly on how the technology industry manages AI vulnerability discovery tools. Establishing comprehensive governance frameworks, access controls and accountability mechanisms will be critical for avoiding misuse whilst enabling legitimate security research. Industry collaboration between technology companies, security researchers, governments and law enforcement could help establish standards for responsible deployment. Such frameworks might feature restricted licensing agreements, usage monitoring, and international collaboration to prevent tools from reaching criminal networks. Without active management, the competitive advantage currently held by ethical hackers could diminish within years.
Chompie’s decision to participate at Pwn2Own whilst the chance persists reflects a wider imperative within the ethical hacking community to establish norms and protections before AI substantially transforms the landscape. Cybersecurity experts, policy officials and tech firms must work together to guarantee that advanced artificial intelligence systems reinforce rather than weaken cybersecurity defences. This demands openness regarding functionality, honest assessment of risks, and willingness to implement restrictions that may create challenges for experts but safeguard critical infrastructure. The window for establishing responsible standards may be narrowing, making immediate action essential to preserving human expertise and ethical oversight in an increasingly automated security ecosystem.