Why did cURL end its bug bounty?
Key summary
CURL project ended its bug bounty program announced end of bug bounty program in January 2026 citing reviewer workload and AI-generated low-quality reports.
CURL policy stopped providing monetary rewards for vulnerability reports stated removal of monetary rewards regardless of severity.
CURL reporting channels migrated vulnerability reporting from HackerOne to GitHub private reporting, hackerOne was removed and reporters were directed to GitHub private vulnerability reporting.
CURL policy will block and publicly flag accounts that submit AI slop reports specified immediate blocking and public identification of accounts submitting AI-generated low-quality reports.
AI slop described as generated reports with plausible form but insufficient reproducible evidence defined as generated reports that appear plausible but lack reproducible evidence.
