DEV Community

NET_DARK_BOI
NET_DARK_BOI

Posted on

curl quit, HackerOne paused, Elastic pays $2 a report: the bug-bounty economy after AI slop

In December 2024 Seth Larson, the Python Software Foundation's security developer-in-residence, described "a new era of slop security reports for open source": vulnerability reports generated by language models, referencing code that does not exist, flagging deliberate design choices as bugs. One report to urllib3 warned that the library was disabling SSLv2 — which it was, on purpose. His summary of the cost was not about money: "Security reports that waste maintainers' time result in confusion, stress, frustration, and to top it off a sense of isolation due to the secretive nature of security reports" (Larson, Dec 2024).

Eighteen months later, the thing he described has repriced an entire market. Here is the timeline, with the numbers traced to their sources.

The timeline

January 2026 — curl ends its bounty. After seven years and 87 confirmed vulnerabilities, curl's HackerOne programme closed on 31 January. Daniel Stenberg's stated goal: "remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not." In one sixteen-hour stretch that month the project received seven reports; none was a vulnerability (BleepingComputer, The Register, RedMonk). Reports were still welcome; the payment was what stopped.

27 March 2026 — HackerOne's Internet Bug Bounty pauses. The IBB, which has paid for fixes in open-source projects since 2013, stopped accepting new submissions. The reason given was not fraud but arithmetic: AI-assisted discovery had outrun the maintainers' capacity to fix, and bounties fund discovery, not remediation (GIGAZINE, Dark Reading).

21 April 2026 — HackerOne starts selling validation. Launching h1 Validation, the platform published its own numbers: submissions up 76% year over year, a record 46,947 in March, about 25% of findings confirmed exploitable, critical-and-high severity up to 32% of the total, and remediation capacity improved by only 19% (HackerOne press release).

6 May 2026 — "Finding Fast, Fixing Slow". HackerOne's product leadership spelled out the asymmetry. Mean time to remediate an individual issue fell by roughly 80%. The number of vulnerabilities actually resolved per month fell by about 46%. The backlog of validated-but-unresolved findings grew more than 21×; unresolved criticals grew 25×; the resolution rate for criticals dropped from over 83% to under 40% (HackerOne, May 2026). Teams are fixing faster and falling further behind.

4 August 2026 — Elastic publishes the cost of a report. Elastic's programme received more than 1,390 reports in the first half of 2026 — more than 2024 and 2025 combined, against a historical 600–850 per year. Roughly 70% are rejected at analysis. Their AI-assisted triage now costs about $0.50–1.15 per report to analyse and $0.80–4.90 to reproduce when reproduction is needed, around $2 on average. The stated cause: "LLMs made it trivially cheap to generate vulnerability reports" (Elastic Security Labs).

For scale: NIST published roughly 50,000 CVEs in 2025, up 22% on the year, and a small company like Screenly reported 331 submissions in under six months, of which 39 were real (RedMonk). The OpenSSF's vulnerability-disclosure working group now has an open work item to write best practices for maintainers facing AI-generated reports (OpenSSF WG issue #178).

Who is sending all this

The senders are not a separate population from the good researchers. They are the same people with the same tools.

HackerOne's ninth Hacker-Powered Security Report (October 2025) found 70% of researchers using AI in their workflow; valid AI-related vulnerability reports were up 210% and valid prompt-injection reports up 540%; 1,121 programmes had AI in scope, a 270% increase (HackerOne, Oct 2025). Bugcrowd's Inside the Mind of a Hacker 2026, drawn from more than 2,000 participants, puts AI adoption among hackers at 82%, up from 64% in 2023, with hackers "automating the search for low hanging fruit vulnerabilities" to spend their time on the complex ones (Bugcrowd, Jan 2026).

So the same tooling produces the valid quarter and the noisy three-quarters. The variable is not the model. It is whether a human verified the reproduction and identified the root cause before pressing submit — the two steps that cost time, and therefore the two steps a volume strategy skips.

The economics, in one paragraph

A bounty pays for discovery. Nobody pays for triage, and nobody pays for the fix; those are absorbed by the programme and the maintainer. When discovery becomes nearly free, its price falls toward zero and the unpaid parts absorb the entire cost of the flood. That is why programmes pause (IBB) or close (curl) while valid findings are rising, and why the platforms' newest products are validation services rather than bigger payouts. RedMonk's Kate Holterhoff put the condition for stability plainly: "Until assessment costs are reduced, fixes are prioritized over mere discoveries, and supply chain security receives executive commitment, the vulnerability management system will accelerate unsustainably" (RedMonk).

What a report that survives triage looks like

Elastic's cost model is the clearest guide, because it shows where the money goes: reports that cannot be reproduced are cheap to close and reports that make reproduction trivial are the ones that get paid. Read from the triage side, a report that gets through has five parts.

  1. An exact reproduction. The request and response, the account and role used, the preconditions. Not "an attacker could" — "this request, from this user, returned this".
  2. The observed effect on test data. What was read, changed or executed, shown, not inferred. A timing difference is a hint, not an impact.
  3. The missing decision. Which check is absent — ownership on the object, parameterisation at the query, an allow-list at the sink — and, where the code is public, which line.
  4. A proposed fix, ideally with the regression test that would have caught it. This is the part maintainers can act on without re-deriving the bug.
  5. A scope and duplicate check done before submission, against the programme's policy and its public issue tracker.

Parts 3 and 4 are the ones that models do not reliably produce and most training does not teach, because most training scores the exploit and stops. They are also the only parts with any remaining market value.

Breachloom's practice track is built to that shape: after each exploit there is a fix-the-code mission in which the server replays the attack against the learner's patch, and the bug-bounty path includes a report template with exactly those five sections:

The bounty market is not dying. It is repricing.

Discovery is heading toward free. Verified reproduction, root cause and a working fix are what is left to pay for — and, judging by the backlog numbers, there has never been more of that work to do.


Sources: Seth Larson — New era of slop security reports for open source (Dec 2024) · BleepingComputer — curl ending bug bounty program (Jan 2026) · The Register — curl shutters bug bounty program (Jan 2026) · GIGAZINE — Internet Bug Bounty pauses new submissions (Apr 2026) · Dark Reading — AI-led remediation crisis prompts HackerOne to pause bug bounties · HackerOne — h1 Validation press release (Apr 2026) · HackerOne — Finding Fast, Fixing Slow (May 2026) · Elastic Security Labs — AI vulnerability triage (Aug 2026) · RedMonk — AI Slop & the Vulnerability Treadmill (May 2026) · OpenSSF — AI-SLOP best practices work item · HackerOne — 9th Hacker-Powered Security Report (Oct 2025) · Bugcrowd — Inside the Mind of a Hacker 2026 (Jan 2026)

Top comments (0)