Merton101 · Case 2 · Open source and security
curl ended its bug bounty after AI-written reports drowned the real ones
Reported 26 Jan 2026 · entered the ledger 25 Sep 2026 · last checked 25 Sep 2026 · Side effect
Since 2019 the programme paid over $100,000 for 87 confirmed vulnerabilities; from 2025 fewer than one report in twenty was real. It stopped on 31 January 2026.
The institution
curl bug bounty
institution
The mechanism
Friction removed
externality scale 2 of 5, fast
Adaptation
price
a cost on the sender; the filter is money again
The case
- The assumption that broke
- A paid report costs the reporter effort, so a reward attracts findings rather than noise.
- The first-order effect
- Confirmed-report rate from above 15% to below 5%; maintainers' time consumed by debunking; the reward removed.
- Who pays
- the maintainers, and legitimate reporters who lose the reward · group: Volunteers and reviewers
- Scale and speed
- 2 of 5 · fast
Evidence
-
daniel.haxx.se ↗
26 Jan 2026
Not even one in twenty was real.
The second reader
| Claim | Verdict | Note |
|---|---|---|
| [number] 87 confirmed vulnerabilities and over 100,000 USD paid as rewards (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) | supported | Page states: "87 confirmed vulnerabilities and over 100,000 USD paid as rewards to researchers." |
| [number] previous years north of 15% of submissions confirmed; starting 2025 below 5% (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) | supported | Page states: "Previous years we have had a rate of somewhere north of 15% of the submissions ending up confirmed vulnerabilities. Starting 2025, the confirmed-rate plummeted to below 5%." |
| [date] the bug-bounty officially stops on January 31, 2026 (from https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/) | supported | Page states: "It officially stops on January 31, 2026." |