Curl shutters bug bounty program to remove incentive for submitting AI slop
(2026/01/21)
- Reference: 1768973387
- News link: https://www.theregister.co.uk/2026/01/21/curl_ends_bug_bounty/
- Source link:
The maintainer of popular open-source data transfer tool cURL has ended the project’s bug bounty program after maintainers struggled to assess a flood of AI-generated contributions.
Curler-in-chief Daniel Stenberg last week lodged a [1]GitHub commit named “BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026”.
Readers may recall that Stenberg started complaining about AI-generated bug reports in [2]early 2024 , and by mid-2025 [3]contemplated killing the project’s bug bounty program. After receiving some strong bug reports that a developer found with help from AI, Stenberg [4]acknowledged that AI can be a fine bug-hunting aid.
[5]
Stenberg addressed his decision in a [6]mailing message that opened with news that last week the project’s bug bounty scheme generated seven submissions and that while some identified bugs, none described a vulnerability.
[7]
[8]
Figuring that out took “a good while.”
He then expressed his hope that ending the bug bounty program will “remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not.”
[9]
“The current torrent of submissions put a high load on the curl security team and this is an attempt to reduce the noise.”
Stenberg’s post also expresses his hope that developers continue to send reports of “actual security vulnerabilities … even if we do not pay for them.”
“The future will tell,” he added, and perhaps reveal not just whether developers will share bug reports, but also if they are willing to risk public criticism if their submissions don’t meet Stenberg’s standards.
[10]Gentoo and NetBSD ban 'AI' code, but Debian doesn't – yet
[11]Microsoft CEO Satya Nadella becomes AI influencer, asks us all to move beyond slop
[12]Just because Linus Torvalds vibe codes doesn't mean it's a good idea
[13]Gentoo and NetBSD ban 'AI' code, but Debian doesn't – yet
Stenberg explained his stance in a section of the post that considers his policy of publicly shaming those who submit “silly AI-generated submissions” to the bounty program.
In that section, he reveals a recent discussion with one of the people he criticized.
[14]
“It was useful for me to make me remember that oftentimes these people are just ordinary misled humans and they might actually learn from this and perhaps even change,” he wrote.
But Stenberg reserved the right to rage in public.
“This is a balance of course, but I also continue to believe that exposing, discussing and ridiculing the ones who waste our time is one of the better ways to get the message through: you should NEVER report a bug or a vulnerability unless you actually understand it – and can reproduce it.”
“If you still do, I believe I am in the right to make fun of – and be angry at – the person doing it,” he added, before conceding that he also needs to restrain himself on some occasions.
“The person might be a teenage kid who did a single one-time mistake and will then move on in life and make excellent stuff in the future,” he wrote. ®
Get our [15]Tech Resources
[1] https://github.com/curl/curl/pull/20312/commits/694141a154a7c08e5571a31c911fda80f200fe3f
[2] https://www.theregister.com/2024/01/04/aiassisted_bug_reports_make_developers
[3] https://www.theregister.com/2025/07/15/curl_creator_mulls_nixing_bug/
[4] https://www.theregister.com/2025/10/02/curl_project_swamped_with_ai/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://lists.haxx.se/pipermail/daniel/2026-January/000143.html
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2024/05/18/distros_ai_code/
[11] https://www.theregister.com/2026/01/02/microsoft_ceo_satya_nadella_calls/
[12] https://www.theregister.com/2026/01/16/linus_torvalds_vibe_coding/
[13] https://www.theregister.com/2024/05/18/distros_ai_code/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Curler-in-chief Daniel Stenberg last week lodged a [1]GitHub commit named “BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026”.
Readers may recall that Stenberg started complaining about AI-generated bug reports in [2]early 2024 , and by mid-2025 [3]contemplated killing the project’s bug bounty program. After receiving some strong bug reports that a developer found with help from AI, Stenberg [4]acknowledged that AI can be a fine bug-hunting aid.
[5]
Stenberg addressed his decision in a [6]mailing message that opened with news that last week the project’s bug bounty scheme generated seven submissions and that while some identified bugs, none described a vulnerability.
[7]
[8]
Figuring that out took “a good while.”
He then expressed his hope that ending the bug bounty program will “remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not.”
[9]
“The current torrent of submissions put a high load on the curl security team and this is an attempt to reduce the noise.”
Stenberg’s post also expresses his hope that developers continue to send reports of “actual security vulnerabilities … even if we do not pay for them.”
“The future will tell,” he added, and perhaps reveal not just whether developers will share bug reports, but also if they are willing to risk public criticism if their submissions don’t meet Stenberg’s standards.
[10]Gentoo and NetBSD ban 'AI' code, but Debian doesn't – yet
[11]Microsoft CEO Satya Nadella becomes AI influencer, asks us all to move beyond slop
[12]Just because Linus Torvalds vibe codes doesn't mean it's a good idea
[13]Gentoo and NetBSD ban 'AI' code, but Debian doesn't – yet
Stenberg explained his stance in a section of the post that considers his policy of publicly shaming those who submit “silly AI-generated submissions” to the bounty program.
In that section, he reveals a recent discussion with one of the people he criticized.
[14]
“It was useful for me to make me remember that oftentimes these people are just ordinary misled humans and they might actually learn from this and perhaps even change,” he wrote.
But Stenberg reserved the right to rage in public.
“This is a balance of course, but I also continue to believe that exposing, discussing and ridiculing the ones who waste our time is one of the better ways to get the message through: you should NEVER report a bug or a vulnerability unless you actually understand it – and can reproduce it.”
“If you still do, I believe I am in the right to make fun of – and be angry at – the person doing it,” he added, before conceding that he also needs to restrain himself on some occasions.
“The person might be a teenage kid who did a single one-time mistake and will then move on in life and make excellent stuff in the future,” he wrote. ®
Get our [15]Tech Resources
[1] https://github.com/curl/curl/pull/20312/commits/694141a154a7c08e5571a31c911fda80f200fe3f
[2] https://www.theregister.com/2024/01/04/aiassisted_bug_reports_make_developers
[3] https://www.theregister.com/2025/07/15/curl_creator_mulls_nixing_bug/
[4] https://www.theregister.com/2025/10/02/curl_project_swamped_with_ai/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://lists.haxx.se/pipermail/daniel/2026-January/000143.html
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2024/05/18/distros_ai_code/
[11] https://www.theregister.com/2026/01/02/microsoft_ceo_satya_nadella_calls/
[12] https://www.theregister.com/2026/01/16/linus_torvalds_vibe_coding/
[13] https://www.theregister.com/2024/05/18/distros_ai_code/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXCx1Fep7AKPD7pP5gea5wAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
ComputerSays_noAbsolutelyNo
Tragedy of the commons
This won’t work
Jan Ingvoldstad
I work at a company with no bug bounty, and we get around 10 "vulnerability reports" a week, sometimes more.
100% artificial incompetence.
HackerOne
Dan 55
Seems [1]they tried to talk to HackerOne about this mid 2025 but I guess HackerOne's decided more AI slop means more engagement so more chance of earning fees.
[1] https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/
One down...