Review is a public good
Security funding and useful AI
The next useful contribution may be a better question - or a test that fails.
The Foundation’s Core security-bounty page describes a funding pool but says scope, reporting instructions and eligibility must be published before bounty submissions are accepted. That is a meaningful readiness boundary. A researcher should not infer permission to test a live service simply because a fundraising page exists.
Another listed effort, the Litecoin Knowledge Hub, describes a retrieval-based AI tool grounded in a managed knowledge base, with integration work still presented as part of the campaign. We have not tested its answer accuracy. Our editorial standard is that retrieval can improve access to evidence without making mistakes impossible: readers still need sources, dates and a correction route. Security researchers, maintainers and educators perform different jobs, but all benefit from a clear record of what was checked. This is also the rule for our own AI-prepared magazine: automated checks are useful, and they must never be relabeled as independent human review.
- Bounty funding does not equal open testing authorization.
- Source-grounded AI still needs checking and corrections.