A researcher used AI to automatically fuzz 1,500 Google APIs, collected 3,600 API keys, and earned $500,000 in bug bounties. The approach involved analyzing Google's internal discovery documents to find vulnerabilities.
Researcher Arvin Shivram used AI to automatically fuzz 1,500 Google APIs, collected 3,600 API keys, and earned $500,000 in bug bounties. He discovered critical vulnerabilities including Google Voice account takeover, YouTube unlisted video leakage, Widevine DRM compromise, and deanonymization of Nest device owners.
The researcher was drawn back to Google research after being invited to bugSWAT Mexico. Building on small projects with Claude, he realized the potential of using AI for large-scale API fuzzing. He collected Google's discovery documents and extracted API keys from over 60,000 Android APKs.
This case demonstrates how AI can be innovatively applied to security research. Large-scale API fuzzing and vulnerability discovery with AI can uncover hard-to-find flaws, posing important implications for corporate security postures.