XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/Security

Why the curl Bug Bounty Ended in 2026: The Truth and What Came Next

XHack

XHack

Author

October 6, 2026

13 min read

Why the curl Bug Bounty Ended in 2026: The Truth and What Came Next

Table of contents

18

The curl Bug Bounty in Numbers

How the curl Bug Bounty Broke in 2025

Why the curl Bug Bounty Ended

What Happened After the curl Bug Bounty Ended

The Twist: Slop Stopped, Volume Didn’t

Why Slop Stopped: What We Know and What We Don’t

What the curl Bug Bounty Ending Means for Hunters

Stenberg’s Recipe for an Excellent Vulnerability Report

Responsible AI-Assisted Hunting: Where XHack AI Fits

FAQ: The curl Bug Bounty, Answered

Why did the curl bug bounty end?

Does curl still pay for vulnerabilities?

Did AI kill the curl bug bounty?

Is curl accepting vulnerability reports?

How should I report a vulnerability to curl?

Is the curl bug bounty coming back?

What did the curl bug bounty teach other programs?

The Bottom Line

By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)

Read this in 30 seconds: The curl bug bounty ended on January 31, 2026 because AI slop buried it, but the sequel is stranger: the slop stopped, the reports got better, and curl still had to pause security reports for a month.

  • The numbers that ended it. Stenberg says over 15% of reports used to be confirmed vulnerabilities, and from 2025 fewer than 5% were. The program had paid over $100,000 for 87 confirmed vulnerabilities.
  • Then slop stopped being the problem. By April 2026, with curl back on HackerOne, the confirmed rate was back to 15-16%, and reports had doubled from 2025.
  • The new problem is capacity. curl refused all vulnerability reports for July 2026, and the maintainers said it felt like relief.
  • curl pays nothing now. Its policy says it never offers rewards for reported vulnerabilities, at any severity.
  • Stenberg published a recipe for an excellent report. It’s nine steps, and almost none of them involve AI.

The headline said AI slop killed the curl bug bounty. The follow-up said AI made curl’s reports better and overwhelmed it anyway.

Most coverage stopped at January, with the program closing and the slop story wrapped up. Daniel Stenberg, curl’s founder, kept writing, and what he’s described since matters more to anyone who hunts bugs than the original shutdown did.

Here’s the full curl bug bounty timeline from his own posts, what actually changed, and what it means for you.

Why the curl bug bounty ended: the confirmed-report rate fell from over 15% to under 5% in 2025, the bounty ended January 31 2026, then the rate returned to 15 to 16 percent by April while report volume doubled
The curl bug bounty: from over 15% valid, to under 5%, and back

The curl Bug Bounty in Numbers

The curl bug bounty ran on HackerOne for years. By the time Stenberg announced its end in a January 26, 2026 post, it had produced 87 confirmed vulnerabilities and over $100,000 in rewards.

For most of that time, he writes, “somewhere north of 15%” of submissions ended up as confirmed vulnerabilities. That’s a healthy ratio for a popular program. Starting in 2025, it fell below 5%, which means fewer than one in twenty was real.

Curl is one of the most widely deployed pieces of software in the world, so the curl bug bounty was a magnet for anyone chasing a payout. The people reading those reports are a handful of volunteers who give curl limited weekly hours.

How the curl Bug Bounty Broke in 2025

Stenberg described how the curl bug bounty was breaking in a July 2025 post titled “Death by a thousand slops.” About 20% of submissions that year were AI slop, he said, and only about 5% were genuine vulnerabilities.

The cost of running the curl bug bounty wasn’t the volume alone. Each report pulled in three or four members of the security team, for anywhere from 30 minutes to three hours each. A report that claims a hallucinated buffer overflow still has to be read, reproduced and disproved by a human.

He listed the tells: tidy bullet points, em-dashes, bold text, words like “delve,” and vulnerabilities that don’t exist in curl’s code. He also keeps a public gist of 49 slop reports from 2023 onward, mostly claiming memory bugs, injection, protocol exploits and broken crypto.

His proposals for the curl bug bounty at the time were to remove the money, charge a refundable fee per report, require a video proof of concept, or require reputation before bounty eligibility. He wanted to “reduce the amount of sand in the machine.”

Why the curl Bug Bounty Ended

By January, the argument was larger than slop. Stenberg named three trends: the mind-numbing AI slop, humans doing worse than ever, and what he called an apparent will to poke holes rather than help. The curl bug bounty paid people to find problems and, in his view, rarely led them to improve curl.

So on January 31 the bounty ended. Stenberg also stopped using HackerOne as the recommended channel, and sent reporters to GitHub’s private vulnerability reporting from February 1. Hunters had been paid for finding and reporting. Now they’d be paid nothing.

Bugcrowd’s guest opinion piece, published February 5, argued that laziness, not AI itself, killed the curl bug bounty. That’s a useful framing for what comes next.

What Happened After the curl Bug Bounty Ended

This is the part most coverage missed. Here’s the sequence from Stenberg’s posts:

DateWhat happened
Jan 26Announces the end of the curl bug bounty, effective Jan 31
Feb 1HackerOne stops being the recommended channel, GitHub private reporting takes over
Feb 25curl security moves again: 15 shortcomings of GitHub’s system listed, including no way to edit the CVE field, no labels, and full reports sent by email
Mar 1HackerOne becomes the official place to report again
Apr 22High-quality chaos: slop is no longer a problem, confirmed rate 15-16%
Jun 15Summer of bliss: no vulnerability reports during July
Jul 1 to Aug 3The pause. What the bliss taught us follows
Sep 2curl 8.22.0 ships with 9 security fixes, 70 days after the previous release

The detour matters. curl left HackerOne and came back within a month because, in Stenberg’s list, GitHub couldn’t label reports as AI slop, couldn’t publish invalid reports, and sent whole reports over email. The platform’s moderation tools were part of what the curl bug bounty had needed all along.

Timeline of the curl bug bounty: ended January 31, moved to GitHub February 1, back to HackerOne March 1, high-quality chaos post April 22, July pause and curl 8.22.0 on September 2
The curl bug bounty timeline: the part most coverage missed

The Twist: Slop Stopped, Volume Didn’t

In his April post, Stenberg wrote that the slop situation “is not a problem anymore.” The confirmed rate was back to and above its pre-AI 2024 level, in the 15-16% range. And reports were arriving at double the 2025 rate, which had already more than doubled the years before.

He says almost every security report now uses AI to some degree, and the quality is high. He can tell by the wording, and by the fact that curl now gets very detailed duplicates “in ways that can’t be done” by humans alone. He notes that reporters rarely say which tool they used, and that curl doesn’t care.

That’s good news for security and bad news for maintainers. Stenberg predicted curl might publish closer to 50 vulnerabilities in 2026, warned the avalanche would make maintainer overload worse, and pointed out it’s also a good time for attackers, who can find the same issues with the same tools before projects have time to fix them. He said an informal poll showed the same shift at Apache httpd, the Linux kernel, Firefox, Python, Ruby, git and many others.

Why Slop Stopped: What We Know and What We Don’t

The April post says slop stopped. It doesn’t spell out why, and we shouldn’t invent a reason for Stenberg.

What changed is clear: the curl bug bounty was gone, and curl was back on HackerOne with its moderation tools. Our reading is that removing the money removed the incentive for low-effort submissions, and that better models made the remaining reports better. That’s inference from the sequence, not something the posts state.

It lines up with the Bugcrowd piece’s point: the problem was effort, and AI made lazy effort cheap. When there’s nothing to win, lazy effort stops being worth it.

What the curl Bug Bounty Ending Means for Hunters

If you hunt open source, or used to hunt the curl bug bounty, three things follow.

  • curl pays nothing, at any severity. Its reporting policy says there is no bug bounty and the project never offers rewards. You hunt it for the CVE, the credit and the skill, not for cash.
  • Maintainer capacity is now the constraint. A project can refuse every report for a month, as curl did in July. After the pause, Stenberg wrote that the maintainers felt a sense of relief, that he’d had no negative comments, and that curl may repeat it.
  • Good AI-assisted reports are welcome, lazy ones aren’t. curl’s policy tells reporters not to paste massive AI-generated explanations and to write briefly “in your own human voice.” Reports through HackerOne only, never by email.

That connects to the rest of our research, which gives the curl bug bounty its wider context. Our guide to whether AI helps you win bug bounties covers how programs are responding, is bug bounty worth it covers the decision, and what bug bounty hunters make covers the money.

Stenberg’s Recipe for an Excellent Vulnerability Report

In June 2026, Stenberg published do excellent vulnerability reports. It’s the most useful thing to come out of the whole saga, and it reads like a checklist:

StepWhat it means in practice
Understand the softwareCheck the behavior isn’t documented. If it is, it probably isn’t a vulnerability
Open with a short human summaryA few sentences on the flaw and its impact, as a reality check
Use the project’s channelNever circumvent the submission method it asks for
Communicate as a humanWhatever AI helped you find it, you write to the maintainers
Include a reproducerStandalone, runnable code that demonstrates the problem
Offer a patchEven an imperfect one. Getting most of the way there helps
State affected versionsThe version you tested, and the earliest vulnerable one if you can bisect
Stay availableClarify, help assess severity, refine the fix, review the advisory
Learn from itTake what you learned into the next report

Look at what’s on the list and what isn’t. Nothing on it is about finding the bug. It’s all about being useful to a tired volunteer, which is the opposite of what slop does.

Stenberg's nine-step recipe for an excellent vulnerability report, from understanding the software and writing a human summary to providing a reproducer, offering a patch, stating affected versions and staying available
The curl maintainer’s recipe for an excellent vulnerability report

Responsible AI-Assisted Hunting: Where XHack AI Fits

We build XHack AI for bug hunters, so weigh this accordingly. It’s designed around the same idea as Stenberg’s recipe: the tool does the heavy lifting and you do the part only you can.

  • Reproduction built in. Each confirmed finding is captured with proof, reproduction steps and the exact HTTP request, which is the raw material for a reproducer.
  • Findings that hold up. Findings now require a CVSS v4.0 rating, a CWE and references, with no severity inflation, and the built-in browser records every request and response into the Repeater so you can replay what you found.
  • A review step before anything is called real. Our agent guide describes findings being logged as evidence first, with a human check before they’re treated as findings.

What it can’t do is write your opening summary, decide whether a behavior is documented, or stay available to the maintainer. Those are on you, and curl’s maintainers are explicit that they want to hear from a person. Access is gated by identity verification, and individual plans start at $20 a month with a 7-day free trial and no credit card.

FAQ: The curl Bug Bounty, Answered

Why did the curl bug bounty end?

Because AI-generated and other low-quality reports buried it. Stenberg says the confirmed-vulnerability rate fell from over 15% to under 5% in 2025, and he cited mind-numbing AI slop, humans doing worse than ever, and a will to poke holes rather than help. It ended January 31, 2026.

Does curl still pay for vulnerabilities?

No. Its reporting policy says there is no bug bounty and the project never offers rewards for reported vulnerabilities. Reports go through HackerOne, which curl returned to on March 1, 2026.

Did AI kill the curl bug bounty?

Partly. AI-generated slop was a main cause. But by April 2026 Stenberg said the slop problem was gone and that almost every report now uses AI to some degree, with the confirmed rate back to 15-16%. Bugcrowd’s guest opinion piece argued the real cause was lazy hacking, not AI itself.

Is curl accepting vulnerability reports?

Yes, through HackerOne. It refused all vulnerability reports for July 2026, reopened on August 3, and Stenberg says it may repeat the pause. It doesn’t accept reports by email.

How should I report a vulnerability to curl?

Follow Stenberg’s nine steps: understand the software, open with a short human-written summary, include a reproducer, offer a patch if you can, state affected versions, and stay available. Don’t paste long AI-generated explanations.

Is the curl bug bounty coming back?

Nothing in Stenberg’s posts or curl’s reporting policy suggests it is. The policy says the project never offers rewards, and the curl bug bounty’s replacement is plain reporting through HackerOne with no payout.

What did the curl bug bounty teach other programs?

That money attracts effort of every quality, that maintainer capacity is a scarce resource, and that AI changes the shape of the problem. Programs have since cut payouts, capped submissions or paused entirely, as we cover in our article on whether AI helps you win bug bounties.

The Bottom Line

The curl bug bounty ended because slop made it unworkable, but the more important fact is what came after: removing the money and returning to better tooling ended the slop, while AI-assisted reports doubled and kept coming. The bottleneck moved from filtering junk to the humans who have to fix real bugs.

For hunters, the lesson is to be the person a maintainer is glad to hear from. Use AI to find and reproduce, then write like a human, include a reproducer, offer a patch, and don’t expect the money. curl’s maintainers took a month off and nothing broke. That’s a better reason to hunt carefully than any bounty table.


Categories

Security

Previous

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

Next

Is Bug Bounty Worth It in 2026? The Honest Verdict

On this page

The curl Bug Bounty in Numbers

How the curl Bug Bounty Broke in 2025

Why the curl Bug Bounty Ended

What Happened After the curl Bug Bounty Ended

The Twist: Slop Stopped, Volume Didn’t

Why Slop Stopped: What We Know and What We Don’t

What the curl Bug Bounty Ending Means for Hunters

Stenberg’s Recipe for an Excellent Vulnerability Report

Responsible AI-Assisted Hunting: Where XHack AI Fits

FAQ: The curl Bug Bounty, Answered

Why did the curl bug bounty end?

Does curl still pay for vulnerabilities?

Did AI kill the curl bug bounty?

Is curl accepting vulnerability reports?

How should I report a vulnerability to curl?

Is the curl bug bounty coming back?

What did the curl bug bounty teach other programs?

The Bottom Line

Related articles

Continue reading

Career Paths After Bug Bounty: 5 Honest Routes From Hunter to Founder

Security

Career Paths After Bug Bounty: 5 Honest Routes From Hunter to Founder

A bug bounty career can lead to pentesting, AppSec, red teaming, the platform side or a company. Five honest routes, wit...

Read article
API Credits: The Complete 2026 XHack AI API Guide

Security

API Credits: The Complete 2026 XHack AI API Guide

API credits for the XHack AI API: how to buy them, create a key, price each request, and connect Codex, Claude Code and ...

Read article
XHack AI Can Make Mistakes: What Goes Wrong, Why, and How to Catch It

Security

XHack AI Can Make Mistakes: What Goes Wrong, Why, and How to Catch It

AI mistakes in pentesting: how XHack AI errs, why they happen, what research shows, and the checks that catch false posi...

Read article