# this makes me really upset

Source: https://www.youtube.com/watch?v=PG5sv20Jiic
Recap page: https://rapidrecap.app/video/PG5sv20Jiic
Generated: 2026-02-06T15:54:09.127+00:00

---
## Quick Overview

The creator of curl, Daniel Stenberg, discontinued the project's HackerOne bug bounty program due to "too strong incentives to find and make up 'problems' in bad faith that cause overload and abuse," leading to an increase in low-quality 'slop' reports, particularly those generated by AI.

**Key Points:**
- Daniel Stenberg discontinued the curl project's HackerOne bug bounty program, effective January 31, 2026.
- The primary reason cited was the influx of low-quality, bad-faith security reports, termed 'slop,' which caused overload and abuse.
- Stenberg explicitly blamed an 'explosion in AI slop reports' starting in late 2024 for accelerating the decline of the program's value.
- The program had successfully paid out over $100,000 USD for 87 confirmed vulnerabilities across curl and libcurl since its inception in April 2019.
- Stenberg highlighted that reporters often tried to twist findings into critical vulnerabilities rather than actively contributing fixes.
- The actions taken include stopping monetary rewards for security reports and ceasing use of HackerOne as the recommended reporting channel for security issues.

![Screenshot at 00:01: The Reddit post headline clearly states the reason for discontinuation: "curl to discontinue its HackerOne / bug bounty due to 'too strong incentives to find and make up 'problems' in bad faith that cause overload and abuse.'"](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-00-01.jpg)

**Context:** The video discusses the decision by Daniel Stenberg, the CEO and primary maintainer of the widely used curl project (and libcurl), to end its bug bounty program hosted on HackerOne. This decision stems from increasing frustration with the quality of submissions received through the platform, particularly citing the negative impact of AI-generated reports ('slop') overwhelming the maintenance team's capacity to handle legitimate security issues.

## Detailed Analysis

Daniel Stenberg decided to discontinue curl's HackerOne bug bounty program on January 31, 2026, citing overwhelming 'slop' reports, many of which he attributes to AI tools like ChatGPT generating low-quality submissions in bad faith. He notes that while the program was successful initially, paying out over $100,000 for 87 confirmed vulnerabilities since 2019, the recent environment has become toxic. Stenberg outlines three main bad trends: mind-numbing AI slop, humans doing worse than AI by trying to twist minor issues into critical ones, and an apparent will to poke holes rather than help. Consequently, curl will no longer offer monetary rewards for security reports and will stop using HackerOne as the recommended channel for reporting security issues, instead directing users to mailing lists or GitHub for security advisories. Stenberg contrasted this situation with recent positive developments, such as receiving the European Open Source Achievement Award, highlighting the irony of the positive recognition alongside the security reporting frustrations. He also briefly reviewed complex vulnerabilities found in curl and libcurl, like a Use-After-Free in libcurl and buffer overflows in curl's IP conversion functions, which were found through manual auditing, suggesting AI tools still struggle with complex, real-world issues.

### Curl Bug Bounty Termination

- Program officially stops on January 31, 2026
- Discontinued due to overload and abuse from 'slop' reports
- No further monetary rewards offered for security reports

### Reasons for Discontinuation

- Explosion of AI-generated 'slop' reports starting in late 2024
- Bad-faith reporting where researchers twist findings into critical vulnerabilities
- Overwhelming workload for the small, unpaid maintenance team

### Program Success Metrics

- Paid over $100,000 USD for 87 confirmed curl/libcurl vulnerabilities since April 2019
- Found vulnerabilities in complex areas like libcurl's SSL keylog callback (Use-After-Free) and curl's IP conversion functions (Buffer Overflow)

### Actions Taken

- Stopped offering monetary rewards for security reports
- Stopped using HackerOne as the recommended channel for reporting security issues
- Directing users to mailing lists or GitHub security advisories instead

### AI Impact on Security Research

- AI tools are cited as contributing significantly to the problem by generating low-quality reports
- Stenberg notes that while AI may eventually help, current tools have a poor signal-to-noise ratio (~1:50) in this context

### Community Interaction

- Showed examples of dismissive responses from staff (e.g., 'AI slop') contrasted with more measured responses acknowledging validation issues in PoCs

![Screenshot at 00:01: Reddit post showing the announcement of curl discontinuing its HackerOne bug bounty program due to abuse and overload.](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-00-01.jpg)
![Screenshot at 00:12: Daniel Stenberg's blog post titled 'THE END OF THE CURL BUG BOUNTY' featuring an image of a pile of money with a 'NO MORE' sign.](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-00-12.jpg)
![Screenshot at 01:58: HackerOne report detailing a high-severity Use-After-Free vulnerability in libcurl, illustrating the type of bugs previously rewarded.](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-01-58.jpg)
![Screenshot at 03:31: HackerOne report showing a Buffer Overflow vulnerability in curl's inet\_ntop functions, highlighting the type of legitimate issues found.](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-03-31.jpg)
![Screenshot at 08:03: The XBOW \(an autonomous offensive security platform\) HackerOne profile showing high activity and numerous resolved bugs, contrasting with curl's decision.](https://ss.rapidrecap.app/screens/PG5sv20Jiic/00-08-03.jpg)
