HeadlinesBriefing favicon HeadlinesBriefing.com

cURL Ends Bug Bounties Over AI Slop Flood

Ars Technica - All content •
×

The cURL project is scrapping its vulnerability reward program at month's end. Founder Daniel Stenberg cited an overwhelming flood of low-quality, AI-generated reports that strain the small open-source team. He stated the move is necessary for the project's survival and maintainers' "intact mental health."

cURL is a foundational internet tool, integrated into Windows, macOS, and Linux for file transfers and troubleshooting. Its security is critical, but the bug bounty system is now overwhelmed. Stenberg noted the issue won't stop at cURL, predicting AI slop will soon plague other software projects.

The team will now publicly ban and ridicule those submitting bogus reports. This decision follows months of complaints from users who fear eliminating bounties harms security. Stenberg praised one researcher who used AI tools effectively, but said most bad reports come from users blindly trusting AI without understanding its output.