/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The curl project plans to end its HackerOne bug bounty program at the end of January, citing a surge in low-quality AI-generated vulnerability reports

The developer of the popular curl command-line utility and library announced that the project will end its HackerOne security bug bounty program …

BleepingComputer Lawrence Abrams

Context & Ripple Effects

curl's move follows a documented escalation: its founder warned in 2024 that easy access to LLMs was producing junk AI-assisted bug reports, and later described the submission burden on HackerOne as resembling a DDoS attack on maintainers.

That makes the decision more than a single program change. It tests whether an open-source project can keep an open bounty intake channel when report triage, rather than vulnerability discovery, becomes the limiting resource.

First-order effects

  • curl will stop accepting reports through its HackerOne bounty program at the end of January, removing that paid disclosure route for researchers targeting the project.
  • Maintainers regain time otherwise spent reviewing low-quality submissions, while HackerOne loses a visible open-source program amid an already strained report-quality workflow.

Second-order effects

  • HackerOne and comparable disclosure platforms face pressure to improve filtering and reporter-quality controls if AI-generated submissions raise triage costs for customers.
  • Researchers seeking rewards for curl findings will need to use the project's remaining disclosure processes, increasing the value of reports that include reproducible, well-evidenced impact.

Third-order effects

  • If other maintainer-led projects follow curl, bug bounty programs may shift from broadly open intake toward tighter eligibility, stronger proof requirements, or curated researcher pools.
  • The case points to AI-generated report volume overwhelming human triage as a quality-governance problem: automation can expand security testing, but its economic value depends on controls that keep validation costs below the benefit of new findings.

The trend: AI is increasing the volume of security claims faster than some open-source teams can validate them, pushing vulnerability-disclosure systems toward stricter quality guardrails.

Discussion

  • @Viss@mastodon.social @Viss@mastodon.social on mastodon
    i was wondering when @bagder would have had enough.  —  looks like “this month”  —  https://www.bleepingcomputer.com/ ...  friends dont let friends bug bounty.  —  ESPECIALLY now that ai is a thing.
  • @weldpond Chris Wysopal on x
    cURL has ended its bug bounty program after being overwhelmed by a flood of low-quality, often AI-generated bug reports that strained its volunteer security team. Maintainer Daniel Stenberg hopes the move will cut noise and encourage real vulnerability reports — even without
  • @pfrazee.com Paul Frazee on bluesky
    RE cURL ending its bug bounty due to slop submissions... yeah.  Both security and recruiting inboxes are being overrun with this kind of thing
  • @k8em0 Katie Moussouris on bluesky
    AI was the accelerant on a perverse incentive fire sparked by bug bounty platforms that reward spray & pray.  Both open source & orgs without dedicated vuln response teams get overloaded when they offer cash there. cURL is right to leave AI shark-infested waters to start fresh.  …
  • @bagder@mastodon.social @bagder@mastodon.social on mastodon
    We seem to have data that confirms that the #curl bug-bounty has received a steep increased submission rate through 2025, while several other Open Source programs also hosted on Hackerone have not.  (There's a graph coming in my pending blog post.)  —  What could possibly be the …
  • r/opensource r on reddit
    Drowning in AI slop, cURL ends bug bounties