Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Blog

Curl Ended Its HackerOne Bug Bounty Over AI-Generated Reports—but Kept a Disclosure Channel

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Curl ended its paid HackerOne bug bounty in January 2026 after a surge in low-quality vulnerability reports that Daniel Stenberg, curl’s lead developer, described as largely AI-generated. But the project did not permanently leave HackerOne: it resumed using the platform for private vulnerability reports on March 1, without offering rewards. As of August 18, 2026, curl’s policy remains disclosure-only.

What curl actually shut down

The announcement concerned the paid bug bounty, not curl’s broader willingness to receive security reports. A bounty offers money for qualifying findings; a vulnerability-disclosure process gives researchers a way to report suspected flaws privately so maintainers can assess and address them. HackerOne can host that process without a bounty attached.

When Stenberg announced the change on January 26, he said the bounty would officially end January 31. Later accounts describe the shutdown as taking effect February 1. Curl briefly moved away from HackerOne, then returned to it as a reporting channel in March. The Internet Bug Bounty had helped fund rewards during the earlier program, but the new arrangement offers no payment for reports. Stenberg’s announcement and his February update explain the transition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the bounty became unsustainable

Stenberg said the bounty had delivered real value, but that a rise in low-quality submissions made the work unsustainable for curl’s small security team. The core problem was not simply that some reports used AI. It was the flow of claims that appeared to be generated without enough independent checking.

#1 Best Overall

A security report is a request for expert investigation. Maintainers may need to reproduce the behavior, check affected versions and configurations, trace the relevant code, and decide whether the issue is exploitable or merely a bug. A confirmed vulnerability can then require a fix, private coordination, a CVE assignment and a public advisory. A false or unsupported claim still consumes time at the front of that process.

In that sense, a high volume of weak submissions can act like a denial-of-service problem: it competes with legitimate reports and ordinary development for scarce maintainer attention. Stenberg described the burden and the bounty’s end in his announcement.

The bounty had produced results before the reporting surge

The program was not a failure from the start. Stenberg said that between its launch in 2019 and its termination, it had led to 87 confirmed vulnerabilities and more than $100,000 in rewards. Those are figures reported by the project lead, not independently audited financial statistics. They show why the decision is better understood as a response to a changed cost-benefit balance than as a verdict that bounty programs have no value.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How curl’s policy changed in 2026

  • January 26: Stenberg announced the end of the paid bounty, setting January 31 as its official end date.
  • February 1: Later commentary describes the shutdown as taking effect.
  • March 1: Curl resumed receiving security reports through HackerOne, with no rewards.
  • April 22: Stenberg reported that low-quality submissions had largely disappeared, while report volume and the share of useful findings had risen.
  • July 1–August 3: Curl paused ordinary vulnerability-report intake, then reopened submissions on August 3.
  • August 18: The official policy still directed suspected vulnerabilities to HackerOne and offered no bounty.

The project’s disclosure policy gives the current route and expectations. Stenberg’s accounts cover the return to HackerOne, the April report-quality update, and the summer pause.

Why curl returned to HackerOne without restoring rewards

The platform and the incentive are separate choices. Curl briefly tried moving away from HackerOne, but Stenberg later said GitHub did not meet the project’s security-reporting needs. Returning to HackerOne preserved a private, structured intake and coordination channel; it did not reopen the bounty.

That distinction matters because a platform can help manage confidential reports and researcher communication, but it cannot guarantee that submissions are accurate. Nor does it remove the project’s responsibility to review them. Curl’s approach kept the reporting route while dropping the financial incentive it considered part of the problem.

AI assistance is not the same as an unverified report

Stenberg’s April account complicates the idea that the project was rejecting AI-assisted security work. He said AI use remained common, but the weak-report problem had largely faded after rewards ended. He described a period of “high-quality chaos”: report volume was roughly twice the 2025 rate, and the confirmed-vulnerability rate had returned to approximately 15–16%, which he characterized as around the pre-AI level. These are curl’s own observations, not an industry-wide measurement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical dividing line is validation. A researcher may use AI to explore code or develop a hypothesis, then check it, understand the affected path and provide reproducible evidence. That differs from submitting model-generated speculation as a finding. A human-written report can also be wrong; authorship alone does not establish quality.

Curl’s policy does not ban AI. It asks reporters to avoid large, lazy AI-generated explanations and make reports clear and digestible. A useful report should distinguish a theoretical concern from an ordinary bug and a security vulnerability, explain impact without inflating severity, and give maintainers a way to reproduce the claim.

What researchers should do before reporting a curl vulnerability

Curl’s current policy directs suspected vulnerabilities to HackerOne, not the public bug tracker or ordinary email. The project handles reports privately until formal disclosure; published issues appear on its security advisory page.

  • Identify the affected curl version and relevant configuration or platform.
  • Explain the security impact and how it differs from a non-security bug.
  • Provide precise reproduction steps or a proof of concept that you have tested.
  • Describe the relevant behavior and evidence in concise, understandable terms.
  • Do not expect a bounty or other payment for a report.

The July intake pause was a specific 2026 measure, not evidence that curl permanently closes submissions every July. During that pause, commercial support arrangements were treated separately from ordinary vulnerability reporting, as Stenberg explained in the summer announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the episode means for open-source security

Curl is widely used as a command-line tool and software library, and assessing a security claim can involve protocol behavior, platform differences, authentication, proxies, TLS and memory safety. A small maintainer team has to balance that work against development and routine project operations.

Stenberg later linked report pressure to fewer feature changes during the curl 8.21.0 development cycle. The June 24, 2026 release nevertheless included 18 security fixes, which he described as a project record for one release and for the number of vulnerabilities published in that calendar year at that point. The episode therefore shows both sides of the capacity problem: security findings can be valuable, and handling them can crowd out other work. Stenberg’s curl posts cover the release and workload.

Other projects could respond in several ways, each with trade-offs. Removing rewards may reduce bounty-driven low-effort submissions but can also deter independent researchers, including those who rely on bounty income. Reputation requirements or demonstrated proof-of-concept rules may improve the signal, but can raise barriers to new researchers. Rate limits, clear scope rules and dedicated triage can control workload, although each needs staff time and does not prevent all false positives. Automation can help deduplicate or classify reports; it should not substitute for human judgment on security impact.

For projects whose users depend on urgent maintainer attention, paid support contracts are another sustainability option, distinct from paying a bounty for a discovered flaw. They can fund support and response capacity, but are not a replacement for broad independent security research. Curl’s summer notice explicitly treated support contracts separately from the paused public intake.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.