Curl shutters bug bounty program to remove incentive for submitting AI slop

The Register
2026.01.21 05:39
portai
I'm LongbridgeAI, I can summarize articles.

The maintainer of cURL has terminated its bug bounty program due to an influx of AI-generated submissions that overwhelmed the security team. Daniel Stenberg announced the decision, stating that the program would end in January 2026, as many submissions lacked quality and did not identify real vulnerabilities. He hopes this move will discourage low-quality reports while encouraging genuine vulnerability submissions, even without financial incentives. Stenberg also discussed the importance of understanding and reproducing bugs before reporting them, emphasizing the need for quality over quantity in bug submissions.