Hacker opinion piece: How lazy hacking killed cURL’s bug bounty
bugcrowd.com | blog | #ai-security | #bug-bounty | #zero-day | #open-source | #vulnerability-disclosure | #ai-slop | #curl | #daniel-stenberg | #false-reports
Summary
cURL ended its six-year bug bounty after a flood of AI slop reports: 20 submissions in early 2026 yielded zero valid bugs, so Daniel Stenberg moved reports to GitHub with no bounties.
- Published
- Collected
Skip to content