FireCompass has announced that its AI-powered penetration testing agent secured Top 3 positions across multiple HackerOne global leaderboards during a three-month live bug bounty experiment conducted on authorised live production systems.
According to the company, the autonomous AI agents independently discovered, validated and responsibly reported vulnerabilities while operating at a cost comparable to a single manual application penetration test. The exercise was carried out on live production environments within authorised programme scopes rather than controlled laboratory settings.
FireCompass said the experiment highlights how AI is making advanced offensive cybersecurity capabilities more accessible, enabling organisations to continuously identify vulnerabilities while also underscoring the need for stronger cyber defence as similar capabilities become more widely available.
The company noted that the experiment is particularly relevant as enterprises accelerate AI adoption while managing increasingly complex cyber threats. It added that continuous AI-powered security validation is becoming more important as advanced penetration testing becomes more affordable.
Bikash Barai, Founder and CEO of FireCompass, said the experiment was designed to understand the cost of reaching the Top 3 positions on a global bug bounty leaderboard. He said the AI agents achieved the milestone with an operating cost of around US$5,000 per month, highlighting that advanced offensive AI capabilities are becoming accessible at a relatively low cost. He added that the focus now should be on engineering safety, controls and accountability alongside more capable AI systems.
Jay Bavisi, Founder and CEO of EC-Council, said the results demonstrate the strength of FireCompass’ technology and engineering. He added that the future of offensive security lies in AI-powered cybersecurity professionals rather than AI replacing human experts. He also highlighted that the experiment incorporated safety measures, including strict programme scope enforcement, non-destructive validation of vulnerabilities, controlled request rates and continued human oversight.
Bruce Schneier, security technologist, author, Harvard lecturer and FireCompass advisor, said the experiment shows that offensive AI can identify real-world vulnerabilities at significantly lower costs. He added that organisations now need to adopt similar capabilities while ensuring they are deployed with appropriate safety and discipline.
FireCompass said its platform combines multiple frontier AI models with purpose-built small language models developed by the company. The experiment incorporated safety controls, including authorised programme scope enforcement, non-destructive vulnerability validation, and limits on request rates, concurrency and operational impact to ensure testing remained within approved boundaries.
Send news announcements/press releases to:
editor@thefoundermedia.com
