LmCast :: Stay tuned in

cURL removes bug bounties

Recorded: Jan. 21, 2026, 11:03 a.m.

Original Summarized

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

cURL removes bug bounties

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.

Annonsera ⏚ Utgivningsplan ⏚ MĂĄnadsmagasinet ⏚ Prenumerera⏚ Konsultguide ⏚ Om oss ⏚  About / Advertise





onsdag 21 januari 2026 VECKA 04

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

A la carte

Nyheter
Produkter
Expertartiklar
Reportage
Teknik
Intervju
Ledare
Debatt
Insändare
Krönika
Analys

Annonsera
Utgivningsplan
Månadsmagasinet
Prenumerera
Konsultguide
Om oss
About/Advertise

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

Kopiera länk till sidan

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

cURL removes bug bounties

Skriv ut

•

Av: Jan TĂĄngring

Publicerad 20 januari 2026

Skapad den 20 januari 2026

Senast uppdaterad 20 januari 2026

Artificiell Intelligens

Open source code library cURL is removing the possibility to earn money by reporting bugs, hoping that this will reduce the volume of AI slop reports. Joshua Rogers – AI wielding bug hunter of fame – thinks it's a great idea.

cURL has been flooded with AI-generated error reports. Now one of the incentives to create them will go away.
The vast majority of AI-generated error reports submitted to cURL are pure nonsense. Other open source projects are caught in the same pandemic.
cURL maintainer Daniel Stenberg made an impact with his reporting on AI-generated bug reports last year – ”Death by a thousand slops.”
Determining that they are nonsense is time-consuming, causing the maintainers lots of extra work.

Daniel
Stenberg

”AI slop and bad reports in general have been increasing even more lately, so we have to try to brake the flood in order not to drown”, says cURL maintainer Daniel Stenberg to Swedish electronics industry news site etn.se.
Therefore, cURL is terminating the bounty payouts as of the end of January.
“We hope this removes some of the incentives for people to send us garbage. We spend far too much time handling slop due to findings that are not real, exaggerated, or misunderstood.”
Not all AI-generated bug reports are nonsense. It’s not possible to determine the exact share, but Daniel Stenberg knows of more than a hundred good AI assisted reports that led to corrections.
In total, 87 bug reports to cURL have over the years amounted to USD 101,020 in bounties.
How many of them would have gone under the radar if the bounty money had not existed?
Elektroniktidningen passes that question on to debugging champion Joshua Rogers, who last year flooded open source projects with bug reports – good reports.
Interestingly, his reports were generated with the help of AI tools. But he doesn’t just vibe along in the dark — he reviews and adds to AI's analysis before submitting anything.
Despite being an active code vulnerabilities hunter himself, he thinks removing the bounty money is a stellar idea ; something that should have been done a long time ago. He documented that view in a 2025 year-end posting.

Joshua
Rogers

“I think it's a good move and worth a bigger consideration by others. It's ridiculous that it went on for so long to be honest, and I personally would have pulled the plug long ago,” he says to etn.se.
But without the bounties an incentive to do code reviews disappears?
”*An incentive*, but not all,” he comments, ”especially for anything that will be reported which actually matters”.
So you think the effect won’t be that big?
“Not much. The real incentive for finding a vulnerability in cURL is the fame ('brand is priceless'), not the hundred or few thousand dollars. $10,000 (maximum cURL bounty) is not a lot of money in the grand scheme of things, for somebody capable of finding a critical vulnerability in curl.”
He realizes, though, that not everyone might share that attitude.
“My view is that there is an asymmetric relationship between developers (open source or not) and so-called "security researchers" (or even real security researchers). Regardless of whether the researchers are in expensive or cheap countries, the value provided to the developer is the same. However, on the flipside, the value of a bounty is not the same for every reporter -- in low socio-economic locations, a reward which would be the cost of lunch in Sweden can be massive for those low socio-economic-located people,” says Joshua Rogers.

Föregående

Nästa

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

Prenumerera pĂĄ Elektroniktidningens nyhetsbrev eller pĂĄ vĂĄrt magasin.

Please enable JavaScript to view the comments powered by Disqus.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.

Halva Tres nät är 5GSA21 jan 2026 11:15 - Per Henricsson Operatören Tre säger sig vara först i Sverige med 5G Standalone (SA) i sitt kommersiella nät. Ungefär hälften av befolkningen täcks sedan slutet av december.
NyheterLäs mer...

Likström genom såret påskyndar läkningen21 jan 2026 09:49 - Per Henricsson Chalmersavknoppningen Bioelectrix vill hjälpa kroppen att få igång läkning av sår genom att applicera en likström via en elektrod av grafen belagd med en ledande polymer. Hos bland annat diabetiker kan de elektriska signalvägarna mellan celler sluta fungera vilket leder till att sår blir större och större.
REPORTAGELäs mer...

Tyskland subventionerar bilar från Kina21 jan 2026 10:27 - Jan Tångring När Tyskland nu återinför elbilsbidrag så får även bilar tillverkade i Kina en del av kakan. Regeringen tror att tyska bilar klarar konkurrensen.
NyheterLäs mer...

Intelligent modul på AMD-processor21 jan 2026 08:58 - Jan Tångring Congatec släpper en datormodul på AMD:s processor Ryzen P100. Den tänkta tillämpningen är edge-AI.
ProduktLäs mer...

PXI med lägre pris21 jan 2026 08:16 - Per Henricsson Med ambitionen att fler ska ha råd med ett PXI-system lanserar NI ett chassi, en kontroller, ett oscilloskopkort och ett IO-kort med ett lägre pris än föregångarna. Tillsammans utgör de ett komplett testsystem.
ProduktLäs mer...

Ingen belöning för buggjakt i Curl20 jan 2026 15:45 - Jan TĂĄngringDet svenskledda kodbiblioteket Curl tar bort möjligheten att tjäna pengar pĂĄ att rapportera buggar och hoppas att det ska minska volymen av AI-slaskrapporter. Buggjägaren Joshua Rogers – som själv flitigt använder debug-bottar –  tycker att det är en bra idĂ©.
NyheterLäs mer...

EU vill stoppa Huawei20 jan 2026 13:16 - Per Henricsson EU-kommissionen har läggt fram en uppdaterad version av cybersäkerhetsakten. Den vill förbjuda kinesiska produkter i kritisk infrastruktur. Om förslaget antas skulle det innebära att länder som inte implementerat EU:s så kallade verktygslåda nu tvingas sätta stopp för Huawei, ZTE och andra kinesiska leverantörer i 5G-näten.
NyheterLäs mer...

Nvidia bjuder in Risc V i AI-datacentret20 jan 2026 11:44 - Jan TĂĄngringAmerikanska Risc V-pionjären Sifive integrerar Nvidias datalänkteknik NV-link Fusion i sin data­center-IP. Därmed kan vi komma att fĂĄ se AI-datacenter med Risc V-cpu:er som pratar med Nvidias AI-acceleratorer.
ProduktLäs mer...

Satelliterna ska fylla hålen i mobilnäten20 jan 2026 09:08 - Göte Andersson Mobilindustrin tar nu sats för ny stor expansion med hjälp av globala satellitsystem. Amerikanska Starlink ligger i täten med en lösning som visar vad detta handlar om, att kommunicera direkt med vanliga mobiltelefoner utan att gå via någon landbaserad basstation i mobilnätet.
REPORTAGELäs mer...

Koldioxidsensor från Delsbo20 jan 2026 08:47 - Per Henricsson S12 är en ultrakompakt sensor för CO₂-mätning från Senseair. Den är utvecklad för batteridrivna och trådlösa system som mäter luftens kvalitet i byggnader.
ProduktLäs mer...

Kina: Batteri och elbil måste skrotas tillsammans19 jan 2026 12:51 - Jan TångringKina kommer att kräva att elbilens batteri sitter kvar i fordonet vid skrotning. Det kommer att får effekter på marknaden för återvinning och återanvändning av batterierna.
NyheterLäs mer...

Snabbladdning sliter dubbelt sĂĄ hĂĄrt pĂĄ batteriet19 jan 2026 11:04 - Jan TĂĄngring Under det senaste ĂĄret har snabbladdandet ökat vilket satt ett dramatiskt avtryck pĂĄ elbilsbatteriernas livslängd. Analysen kommer frĂĄn telematikföretaget  Geotab.
NyheterLäs mer...

Kanada öppnar för kinesiska elbilar och samarbeten19 jan 2026 11:04 - Jan Tångring USA och Kanada har inte längre en enad handelsfront mot Kina efter att Kanadas och Kinas ledare skakat hand om en friare handel med bland annat elbilar och energiteknik. Polestar, Volvo och Tesla hoppas snabbt kunna återställa sin försäljning.
NyheterLäs mer...

Micron köper fab i Taiwan19 jan 2026 10:25 - Per Henricsson Amerikanska Micron har tecknat en avsiktsföklaring om att köpa en halvledarfabrik i Taiwan av foundryt PSMC, Powerchip Semiconductor Manufacturing Corporation. För 1,8 miljarder dollar får minnesjätten ett toppmodernt renrum på 2 800 kvadratmeter med 300 mm-maskiner.
NyheterLäs mer...

Armarnas rörelser avslöjar stroke19 jan 2026 08:47 - Per Henricsson Genom att mäta armarnas rörelser med vad som kan beskrivas som två aktivitetsarmband går det att upptäcka ett strokeinsjuknande och automatiskt skicka ett larm. Lundabolaget Uman Sense håller på att kommersialisera tekniken som just nu testas på åtta svenska sjukhus.
REPORTAGELäs mer...

Micron sätter spaden i marken16 jan 2026 14:38 - Per Henricsson Den amerikanska minnestillverkaren Micron startar officiellt bygget av sin nya megafabrik i delstaten New York idag sedan alla nödvändiga tillstånd är beviljade.
NyheterLäs mer...

Uppgifter: Nvidias superprocessor får inte föras in i Kina16 jan 2026 10:48 - Jan Tångring Kinesiska tullmyndigheter meddelade denna vecka sina tulltjänstemän att Nvidias kontroversiella processor H200 inte får tas in i Kina. Det har tre personer med insyn berättat för nyhetsbyrån Reuters.
NyheterLäs mer...

Tysk standard för batteribyte redo för utrullning16 jan 2026 09:13 - Jan TĂĄngring Efter att ha tagit fram, och under tvĂĄ ĂĄr testat, en lösning för automatiskt batteribyte för tunga lastbilar, vill ett tyskt konsortium bygga ett nätverk av standardiserade serieproducerbara batterimackar i Europa. 
NyheterLäs mer...

Flygvapnet öppnar dörren för Uppsalas inkubator16 jan 2026 09:32 - Per Henricsson Uppsala Innovation Centre, UIC, och Flygvapnet har startat ett samarbete som ska underlätta för uppstartsbolagen att hitta behovsägare inom Försvarsmakten och initiera pilotprojekt.
NyheterLäs mer...

Mips får sällskap av Arc hos Globalfoundries16 jan 2026 08:23 - Per Henricsson Så sent som i somras köpte amerikanska Globalfoundries IP-leverantören Mips. Nu får Risc V-kärnorna sällskap av Arc:s kärnor, som Synopsys säljer till foundryt.
NyheterLäs mer...

MER LÄSNING:
Uppsalas natriumjonmaterial ska tillverkas i TjeckienTestlösning Ethernet i fordonMikroskopiska soldrivna robotar dansar i vattenStorvarsel på EricssonOpen AI beställer ”tallriksprocessorn”Ryzen för fordon och fysisk AISvenskt drönarskydd i DavosMercedes utmanar Teslas självkörningFinansieringsproblem sinkar Lytens köp av NorthvoltSiemens köper franskt verktyg för korttest

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

 

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

KOMMENTARER

Kommentarer via

Disqus

JavaScript is currently disabled.Please enable it for a better experience of Jumi.


Bidrag frĂĄn
branschens experter

Altium: Kan halvledarindustrin ta hĂĄllbarhet pĂĄ allvar?

Halvledarindustrin är inte van vid att framställas som en miljöbov. Den är motorn bakom de flesta...

Alif Semiconductor: Generativ AI ställer nya krav på styrkretsen

Stora språkmodeller (LLM:er) och tjänster baserade på dessa som ChatGPT och Gemini är lysande...

Bytesnap: Egensäker elektronik – igår och idag

Historiskt sett var elektronik som var avsedd för farliga miljöer, så kallad egensäker (IS)...

Nya produkter

Intelligent modul pĂĄ AMD-processor

Congatec släpper en datormodul på AMD:s processor Ryzen P100. Den tänkta tillämpningen är edge-AI.

PXI med lägre pris

Med ambitionen att fler ska ha rĂĄd med ett PXI-system lanserar NI ett chassi, en kontroller, ett...

Nvidia bjuder in Risc V i AI-datacentret

Amerikanska Risc V-pionjären Sifive integrerar Nvidias datalänkteknik NV-link Fusion i sin data­center-IP....

Koldioxidsensor frĂĄn Delsbo

S12 är en ultrakompakt sensor för CO₂-mätning från Senseair. Den är utvecklad för batteridrivna...

Ryzen för fordon och fysisk AI

P100 heter en ny x86-processorfamilj bestyckad med Zen 5-cpu:er, RDNA 3.5-gpu:er och sist men inte...

Senaste nyheter

Halva Tres nät är 5GSA

Operatören Tre säger sig vara först i Sverige med 5G Standalone (SA) i sitt kommersiella nät....

Tyskland subventionerar bilar frĂĄn Kina

När Tyskland nu återinför elbilsbidrag så får även bilar tillverkade i Kina en del av kakan....

cURL removes bug bounties

Open source code library cURL is removing the possibility to earn money by reporting bugs, hoping...

Ingen belöning för buggjakt i Curl

Det svenskledda kodbiblioteket Curl tar bort möjligheten att tjäna pengar på att rapportera buggar...

EU vill stoppa Huawei

EU-kommissionen har läggt fram en uppdaterad version av cybersäkerhetsakten. Den vill förbjuda...

Prenumeration
Annonsering
Om Elektroniktidningen

RainerRaitasuo

+46(0)734-171099 rainer@etn.se
(sälj och marknads­föring)

PerHenricsson

+46(0)734-171303 per@etn.se
(redaktion)

JanTångring

+46(0)734-171309 jan@etn.se
(redaktion)

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.
JavaScript is currently disabled.Please enable it for a better experience of Jumi.

JavaScript is currently disabled.Please enable it for a better experience of Jumi.

cURL, a widely used open-source tool for transferring data using network protocols, is implementing a significant shift in its approach to bug bounty reporting. This change, spearheaded by Daniel Stenberg, the maintainer of cURL, aims to mitigate the overwhelming influx of artificially generated “slop” reports stemming primarily from the rise of artificial intelligence. The core motivation is to reduce the time and resources spent by Stenberg and his team in validating and addressing these reports, many of which are nonsensical or overly broad. Joshua Rogers, a prominent bug hunter who has frequently utilized cURL, has enthusiastically embraced this decision, viewing it as a long overdue and beneficial step.

The problem cURL has faced is largely attributable to the increasing deployment of AI tools for security testing. While AI can undoubtedly assist in identifying vulnerabilities, it has also led to a proliferation of automated reports, frequently containing irrelevant or inaccurate findings. These AI-generated "slop reports," as Daniel Stenberg describes them, severely impact the maintainers' ability to focus on genuine security issues. The sheer volume of these reports, many generated without human oversight or understanding, has created an unsustainable workload. This situation, characterized by Stenberg as “AI slop and bad reports in general,” has been escalating, necessitating a proactive intervention.

As a direct response to this trend, cURL is terminating its bounty program as of the end of January. The intention is to remove the incentives that drive the generation of these low-quality reports. Stenberg explicitly states that the removals of this incentive is ‘to remove some of the incentives for people to send us garbage.’ The monetary rewards, even relatively modest, encourage individuals to create and submit reports, some of which fall far outside the scope of legitimate security analysis. While recognizing the value of genuine contributions from skilled security researchers, Stenberg acknowledges that the current situation has become untenable.

Despite the removal of the financial incentive, the decision is not universally viewed as detrimental. Joshua Rogers, who has been instrumental in identifying vulnerabilities within cURL using an AI-assisted approach, believes that this change is a positive development. He contends that the focus should be on fostering genuine expertise and thoughtful investigation rather than solely relying on monetary rewards. Furthermore, Rogers highlights the substantial number of valuable reports generated through AI assistance – over one hundred good AI assisted reports that led to corrections – underscoring the potential of AI when employed responsibly.

The move raises several pertinent questions about the relationship between open-source development, security research, and the evolving landscape of vulnerability discovery. The value of a bounty, in Rogers’ view, isn’t solely measured in dollars. He posits that the real incentive lies in the "brand is priceless" – creating recognition and reputation among security professionals. The potential maximum cURL bounty of USD 10,000, while offering a substantial reward, is not seen as a sufficient deterrent for a skilled security researcher. Rogers’ perspective introduces a nuanced view, emphasizing that a more significant motivator is the opportunity to contribute meaningfully to a widely used and respected open-source project.

However, the removal of bounties doesn’t negate the potential for value from AI-assisted discovery. Rogers argues that the primary benefit lies in identifying critical vulnerabilities that would otherwise be missed due to the volume of irrelevant reports. He believes that the fundamental incentive remains the pursuit of valuable security knowledge, regardless of monetary compensation. The decision ultimately reflects a strategic refocusing by cURL's maintainers in light of the disproportionate effect of AI-generated slop reports on their workflow. It highlights the need for developers to thoughtfully consider the potential impacts of emerging technologies on their projects and to implement measures to mitigate unwanted or unproductive behaviors. The shift acknowledges that simply rewarding vulnerability reports isn't always the most effective strategy, especially when faced with the flood of automated, low-quality findings.