Curl Creator Considers Ending Bug Bounty Program Due to AI-Generated Submissions
Daniel Stenberg, the creator of the popular curl utility, is contemplating whether to end the project’s bug bounty program due to a surge in low-quality, AI-generated reports. Since 2025, around 20% of all submissions have been identified as AI-generated, overwhelming the small team responsible for reviewing them. Stenberg has noted a drastic decline in the quality of bug reports, with only 5% of submissions being valid vulnerabilities. Despite attempts to discourage AI-assisted submissions, the situation continues to worsen, forcing Stenberg to reevaluate the future of the program. The curl bug bounty program, which is hosted on HackerOne, currently requires reporters to disclose if they used AI in their submissions, although it does not entirely ban AI-generated reports. The challenge lies in the fact that many of these reports are submitted by individuals who, albeit well-intentioned, are unaware that they are using unreliable information generated by AI. Stenberg is considering several possible solutions, including charging a fee to submit a report or completely removing the bug bounty rewards, although he remains unsure about these approaches. The problem is compounded by the small size of the curl security team, which consists of only seven people, making it difficult to handle the increased volume of submissions.
