Curl will stop bug bounties program due to avalanche of AI slop


  • Curl ends HackerOne bug bounty due to fake and AI-generated vulnerability reports
  • Developers say incentives led to abuse and overwhelmed the security team with invalid submissions
  • From February 2026, bug reports will be moved to GitHub without financial rewards

The developers of curl, the open source command line tool and software library, are killing their HackerOne bug bounty program because they are being inundated with fake issues and vulnerabilities.

In a new advisory published on GitHub, it was said that the program will sunset at the end of January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top