Curl to pause bug bounty program due to avalanche of AI bugs



  • Curl ends HackerOne bug bounty due to fake, AI-generated vulnerability reports
  • Developers say incentives led to abuse, overwhelming security team with invalid submissions
  • Starting February 2026, bug reports will be moved to GitHub without financial reward

The developers of curl, the command-line tool and open source software library, are removing their HackerOne bug bounty program because they are inundated with fake issues and vulnerabilities.

In a new notice posted on GitHub, it was said that the program will end at the end of January 2026.



Leave a Comment

Your email address will not be published. Required fields are marked *