Curl to shut down bug bounty program due to avalanche of AI garbage


  • Curl Ends HackerOne Bug Bounty Due to Fake AI-Generated Vulnerability Reports
  • Developers say incentives led to abuse, overwhelming security team with invalid submissions
  • Starting February 2026, bug reports will be pushed to GitHub without financial reward

The developers of curl, the open source command line tool and software library, are killing their HackerOne bug bounty program because they are inundated with fake issues and vulnerabilities.

In a new notice posted on GitHub, it was stated that the program will end at the end of January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top