The curl project plans to end its HackerOne bug bounty program at the end of January, citing a surge in low-quality AI-generated vulnerability reports
The developer of the popular curl command-line utility and library announced that the project will end its HackerOne security bug bounty program …
Context & Ripple Effects
curl's move follows a documented escalation: its founder warned in 2024 that easy access to LLMs was producing junk AI-assisted bug reports, and later described the submission burden on HackerOne as resembling a DDoS attack on maintainers.
That makes the decision more than a single program change. It tests whether an open-source project can keep an open bounty intake channel when report triage, rather than vulnerability discovery, becomes the limiting resource.
First-order effects
- curl will stop accepting reports through its HackerOne bounty program at the end of January, removing that paid disclosure route for researchers targeting the project.
- Maintainers regain time otherwise spent reviewing low-quality submissions, while HackerOne loses a visible open-source program amid an already strained report-quality workflow.
Second-order effects
- HackerOne and comparable disclosure platforms face pressure to improve filtering and reporter-quality controls if AI-generated submissions raise triage costs for customers.
- Researchers seeking rewards for curl findings will need to use the project's remaining disclosure processes, increasing the value of reports that include reproducible, well-evidenced impact.
Third-order effects
- If other maintainer-led projects follow curl, bug bounty programs may shift from broadly open intake toward tighter eligibility, stronger proof requirements, or curated researcher pools.
- The case points to AI-generated report volume overwhelming human triage as a quality-governance problem: automation can expand security testing, but its economic value depends on controls that keep validation costs below the benefit of new findings.
The trend: AI is increasing the volume of security claims faster than some open-source teams can validate them, pushing vulnerability-disclosure systems toward stricter quality guardrails.