curl, which is one of the most popular CLI/API tools for network requests and data transfer on Linux/Unix, is to discontinue its HackerOne bug bounty program due to "too strong incentives to find and make up 'problems' in bad faith that cause overload and abuse".
The authors simply cannot keep up with LLM-generated fake security reports created to collect money using bots. So, it now shuts down at the end of January 2026. This is why we can't have good things
github.com/curl/curl/pull/2031…
BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder · Pull Request #20312 · curl/curl
Remove mentions of the bounty and hackerone.GitHub
reshared this


Alex Chapman
in reply to tunmi13 • • •Seedy!
in reply to Alex Chapman • • •johann
in reply to Seedy! • • •I'd rather just go with Firefox with all the AI crap disabled.
tunmi13
in reply to johann • • •