The cURL project ended its bug bounty program after maintainers reported being overwhelmed by a surge of low-quality, often AI-generated submissions that consumed significant triage time without yielding actionable security findings. cURL maintainer Daniel Stenberg documented the decision in a GitHub change (BUG-BOUNTY.md) indicating the bounty would stop at the end of January 2026, citing the “torrent” of submissions and the operational burden placed on the project’s security team.
Stenberg said recent bounty activity included multiple submissions that required substantial effort to assess yet did not describe actual vulnerabilities, and he expressed hope that removing financial incentives would reduce “crap and non-well researched reports,” whether AI-generated or not. While acknowledging that AI can sometimes assist in finding legitimate bugs, he encouraged researchers to continue reporting real security vulnerabilities even without payment, noting that the impact of ending the bounty on future reporting quality remains to be seen.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The cURL project's bug bounty program was set to terminate at the end of January 2026 as part of an effort to reduce noise and remove incentives for poorly researched submissions. Stenberg said he still hoped researchers would continue reporting legitimate vulnerabilities without payment.
Daniel Stenberg said the cURL project would end its bug bounty program at the end of January 2026 after an influx of low-quality, often AI-generated submissions created significant review overhead. He communicated the decision in a GitHub commit and a mailing list message, saying recent bounty reports did not describe actual security vulnerabilities.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.