Key takeaways
- bounty program after triage was consumed by phantom bugs, following curl’s decision to terminate its six-year program after AI slop reached 20% of incoming reports.
- Structural countermeasures: Open-source maintainers and standards bodies like OpenSSF are pivoting from open submission queues toward intentional friction, including reputation gating, submission deposits, and proof-of-code requirements.
Open-source security is experiencing an unprecedented structural breakdown: automated AI bug bounty slop has made public vulnerability reward programs unsustainable for maintainers. By collapsing the marginal cost of report generation to fractions of a cent, large language models enable low-effort hunters to deluge open queues with superficially formatted, completely fabricated security advisories. Triage requires senior maintainers to spend hours debunking non-existent flaws, turning a mechanism designed to protect public infrastructure into an asymmetric denial-of-service attack on developer attention. When the cost to submit an exploit is zero and the cost to verify it remains fixed in expensive human hours, the traditional open bounty model collapses under the weight of synthetic noise.
The consequences are no longer theoretical. High-profile open-source projects including Turso and curl have permanently shuttered their public bug bounty programs after maintainers spent months drowning in automated, hallucinated submissions. This shift represents the death of an economic model that protected the software supply chain for decades.
The Economic Collapse of Asymmetric Triage
For more than fifteen years, open-source bug bounties operated under an implicit economic balance. A software project offered a financial payout for verified security vulnerabilities. In return, independent security researchers spent hours analyzing source code, setting up local harnesses, and constructing reproducible proofs of concept. Because discovering a genuine flaw and writing an actionable exploit took substantial skill and time, submission volume was naturally self-throttling. The inflow of vulnerability tickets roughly matched the rate of legitimate discoveries, remaining within the triage capacity of a small, dedicated engineering team.
Cheap generative inference dismantled that equilibrium within eighteen months. Today, a script invoking an LLM API can inspect a public GitHub repository, hallucinate a plausible vulnerability report complete with standard CVSS scoring, and submit it through a public bug bounty portal for roughly a tenth of a cent. The submitter does not need to understand the codebase, verify the syntax, or confirm whether the target components actually interact.
However, the triage burden cannot be compressed. Verifying a bug report requires the unbroken concentration of the lead engineers who understand the architecture. A maintainer must read the prose, cross-reference the cited files, determine whether the described execution path is feasible, and often build test suites to confirm that an exploit does not reproduce. As a result, the economics have become entirely asymmetric: ten seconds of automated text generation imposes thirty minutes of manual engineering analysis.
Once submission volume surpasses triage bandwidth, the queue never stabilizes. It accumulates until maintainers experience severe burnout or terminate their intake pipelines entirely. Inserting another language model into the triage loop fails to solve the dilemma; automated filtering merely creates an adversarial target where submitters optimize their prompts to bypass the triage classifier, leaving the core human bottleneck unresolved.
Phantom Vulnerabilities and Hallucinated Exploits
The daily reality of triage exhaustion is evident in recent postmortems from leading open-source projects. Turso retired its bug bounty program after its $1,000 reward tier for critical vulnerabilities became an unmanageable magnet for synthetic noise. Turso, an SQLite-compatible database written in Rust, received submissions that ranged from technically nonsensical to outright bizarre. One automated report claimed to have discovered a critical security vulnerability that permitted an attacker to execute arbitrary SQL statements—against a relational SQL database engine designed precisely to evaluate SQL queries. Another submission reported a critical buffer overflow, but the reproduction steps instructed maintainers to manually modify Turso’s Rust source code, force an unsafe volatile write beyond vector bounds, recompile the binary, and execute the corrupted binary to demonstrate memory unsafety.
The crisis reached a tipping point for foundational internet infrastructure when the curl project officially terminated its bug bounty program on January 31, 2026. The move concluded a six-year program that had resolved 87 verified vulnerabilities and paid out more than $100,000 to ethical hackers. As documented by project founder Daniel Stenberg in July 2025 during his analysis of maintainer exhaustion caused by AI slop, synthetic submissions surged to approximately 20% of all incoming reports, while the true positive discovery rate for legitimate vulnerabilities fell to barely 5%.
Following the shutdown, curl discontinued HackerOne as its primary intake funnel. Instead of maintaining an open public bounty surface, curl now requires researchers to report security findings privately through GitHub Security Advisories or its direct disclosure channels, explicitly eliminating monetary incentives that attract automated scraping.
| Project | Bounty Program History | Documented Triage Impact | Policy Outcome |
|---|---|---|---|
| Turso | Offered $1,000 for critical bugs in Rust SQLite database | Maintainer queue flooded with hallucinated memory corruption and SQL execution claims | Permanently retired bug bounty program |
| curl | Operated 6-year program, 87 verified flaws, >$100,000 paid | AI slop reached 20% of inbound volume; genuine flaws dropped to 5% of submissions | Terminated program on Jan 31, 2026; abandoned HackerOne for private GitHub advisories |
Tragedy of the Commons in Open-Source Security

The flood of synthetic vulnerability reports is part of a broader systemic failure across open collaboration platforms. In an industry glossary update, Bugcrowd defined cybersecurity AI slop as unverified, low-evidence, high-volume automated output—including superficially plausible but non-existent vulnerability claims—that degrades triage quality and depletes human defensive capacity. Rather than uncovering novel zero-day vectors, automated scanners wrap generic static analysis outputs in confident prose, mimicking legitimate disclosure documentation without validating whether an exploit vector exists.
This dynamic mirrors the classic economic tragedy of the commons. A comprehensive study on developer sentiment published on arXiv analyzing 1,154 technical discussions framed AI slop as a structural externality: individual actors exploit cheap generative tooling to harvest potential payouts or pad resumes, while shifting the heavy costs of review, verification, and emotional fatigue onto maintainers. This dynamic parallels enterprise environments, where automating threat surfaces without contextual validation collapses defensive perimeters, as explored in TechNode HQ’s analysis of why AI killed security through obscurity in enterprise systems.
The scale of disruption prompted the Open Source Security Foundation (OpenSSF) to step in. Through its Vulnerability Disclosures Working Group, OpenSSF launched an initiative on AI slop best practices to help project maintainers defend against distributed denial-of-service conditions affecting pull request queues, issue trackers, and security inboxes. When defensive teams spend their limited working hours filtering LLM noise, real vulnerabilities slip through unaddressed.
Reintroducing Structural Friction into Intake Queues
Because automated generation cannot be stopped at the protocol layer, software communities are abandoning the philosophy of frictionless submission that guided the web for twenty years. As outlined in Browy’s analysis of bug bounty collapse, maintainers are actively testing several structural friction mechanisms to restore economic balance:
- Refundable submission deposits: Researchers deposit a small sum—such as $20—when lodging a bounty report. The deposit is refunded upon triage confirmation of a valid vulnerability or reputable effort, but forfeited if the report is classified as unverified synthetic slop. While economically sound, this mechanism risks excluding researchers without corporate credit cards or access to international payment rails.
- Reputation and identity gating: First-time reporters must provide verifiable identity credentials, peer references, or pass pre-screening before gaining submission access, while established researchers with verified track records receive expedited review queues.
- Proof of code: Before submitting a vulnerability report to a project, a researcher must have previously contributed a merged pull request to the codebase. The contribution does not need to touch security architecture, but it forces the submitter to demonstrate genuine comprehension of the repository’s build pipelines and runtime logic, rendering automated shotgun prompt scripts ineffective.
- Defensive honeypot repositories: Projects deploy decoy repositories designed specifically to attract automated LLM vulnerability scanners, capturing submitter identities and feeding shared blocklists across the open-source ecosystem.
Bottom line
The collapse of open-source bug bounties marks the end of frictionless public vulnerability disclosure. When text generation is free, open submission forms inevitably become targets for automated extraction. For engineering leaders and open-source foundations, preserving maintainer attention requires abandoning open queues in favor of authenticated disclosures, reputation gating, and proof-of-work mechanics. Projects that fail to introduce deliberate friction will see their most experienced engineers burn out filtering synthetic noise, leaving core infrastructure exposed to real, unmonitored security threats.
Sources
- The Wonders of AI: We Are Retiring Our Bug Bounty Program
- The end of the curl bug-bounty | daniel.haxx.se
- Death by a thousand slops | daniel.haxx.se
- curl Shuts Down Bug Bounty Program After Flood of AI Slop Reports | Socket
- “An Endless Stream of AI Slop”: How Developers Discuss the Burden of AI-Assisted Software Development
- AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures · GitHub
- What Is AI Slop? Meaning, Cybersecurity Risks, and Bug Bounty Examples
- AI slop killed the open-source bug bounty | Browy



