• Curl will stop bug bounties program due to avalanche of AI slop

    From TechnologyDaily@1337:1/100 to All on Fri Jan 23 17:15:08 2026
    Curl will stop bug bounties program due to avalanche of AI slop

    Date:
    Fri, 23 Jan 2026 17:10:00 +0000

    Description:
    A small team was being bombarded with submissions, many of which were low-quality, or AI-generated.

    FULL STORY ======================================================================Curl ends HackerOne bug bounty due to fake and AI-generated vulnerability reports Developers say incentives led to abuse, overwhelming the security team with invalid submissions From February 2026, bug reports move to GitHub with no financial rewards

    The developers of curl, the open source command-line tool and software library, are killing their HackerOne bug bounty program because they are
    being flooded with fake problems and vulnerabilities.

    In a new advisory published on GitHub, it was said that the program is being sunsetted at the end of January, 2026.

    Up until the end of January 2026 there was a curl bug bounty. It is no more, the document reads. The curl project no longer offers any rewards for
    reported bugs or vulnerabilities. We also do not aid security researchers to get such rewards for curl problems from other sources either. Straining the security team

    The document then describes the state of the bug bounty program which, apparently, did not serve its purpose:

    We have concluded the hard way that a bug bounty gives people too strong incentives to find and make up "problems" in bad faith that cause overload
    and abuse. We still appreciate and value valid vulnerability reports.

    Citing curls founder and lead developer, Daniel Stenberg, BleepingComputer reported that the problem is that researchers are using Generative Artificial Intelligence (GenAI) to create AI slop reports.

    The same source says Stenberg recently mailed his followers, explaining how these poor reports are hurting the security team:

    "We started out the week receiving seven HackerOne issues within a sixteen-hour period. Some of them were true and proper bugs and taking care
    of this lot took a good while. Eventually we concluded that none of them identified a vulnerability and we now count twenty submissions done already
    in 2026," Stenberg said.

    "The main goal with shutting down the bounty is to remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not. The current torrent of submissions put a high load on the curl security team and this is an attempt to reduce the noise.

    As of February 2026, all bug reports will go directly through GitHub and will not be paid for.

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the
    Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/curl-will-stop-bug-bounties-program-due -to-avalanche-of-ai-slop


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)