
- Curl ends HackerOne bug bounty due to fake and AI-generated vulnerability reports
- Developers say incentives led to abuse, overwhelming the security team with invalid submissions
- From February 2026, bug reports move to GitHub with no financial rewards
The developers of curl, the open source command-line tool and software library, are killing their HackerOne bug bounty program because they are being flooded with fake problems and vulnerabilities.