Switch language한국어
Back to the list

Why did cURL end its bug bounty?

TL;DR AI

Key summary

2 min read
  1. CURL project ended its bug bounty program announced end of bug bounty program in January 2026 citing reviewer workload and AI-generated low-quality reports.

  2. CURL policy stopped providing monetary rewards for vulnerability reports stated removal of monetary rewards regardless of severity.

  3. CURL reporting channels migrated vulnerability reporting from HackerOne to GitHub private reporting, hackerOne was removed and reporters were directed to GitHub private vulnerability reporting.

  4. CURL policy will block and publicly flag accounts that submit AI slop reports specified immediate blocking and public identification of accounts submitting AI-generated low-quality reports.

  5. AI slop described as generated reports with plausible form but insufficient reproducible evidence defined as generated reports that appear plausible but lack reproducible evidence.

Read the original