targeting.ai Society Signal

Merton101 · Case 2 · Open source and security

curl ended its bug bounty after AI-written reports drowned the real ones

Reported 26 Jan 2026 · entered the ledger 25 Sep 2026 · last checked 25 Sep 2026 · Side effect

Since 2019 the programme paid over $100,000 for 87 confirmed vulnerabilities; from 2025 fewer than one report in twenty was real. It stopped on 31 January 2026.

The institution curl bug bounty institution
The mechanism Friction removed externality scale 2 of 5, fast
Adaptation price a cost on the sender; the filter is money again
The case as the ledger holds it
The assumption that broke
A paid report costs the reporter effort, so a reward attracts findings rather than noise.
The first-order effect
Confirmed-report rate from above 15% to below 5%; maintainers' time consumed by debunking; the reward removed.
Who pays
the maintainers, and legitimate reporters who lose the reward · group: Volunteers and reviewers
Scale and speed
2 of 5 · fast
Evidence 1 page read
The second reader every claim, checked against the page
ClaimVerdictNote
[number] 87 confirmed vulnerabilities and over 100,000 USD paid as rewards (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) supported Page states: "87 confirmed vulnerabilities and over 100,000 USD paid as rewards to researchers."
[number] previous years north of 15% of submissions confirmed; starting 2025 below 5% (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) supported Page states: "Previous years we have had a rate of somewhere north of 15% of the submissions ending up confirmed vulnerabilities. Starting 2025, the confirmed-rate plummeted to below 5%."
[date] the bug-bounty officially stops on January 31, 2026 (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) supported Page states: "It officially stops on January 31, 2026."