
curl quit, HackerOne paused, Elastic pays $2 a report: the bug-bounty economy after AI slop
In 2026 curl closed its bug-bounty programme, HackerOne paused its Internet Bug Bounty, and Elastic published what one report costs to read: about two dollars on average. AI-generated submissions repriced the market for vulnerability discovery.
In December 2024 Seth Larson, the Python Software Foundation's security developer-in-residence, described "a new era of slop security reports": submissions written by language models, pointing at code that does not exist and flagging deliberate design choices as bugs. One report to urllib3 complained that the library disabled SSLv2, which it did on purpose. Such reports, Larson wrote, bring "confusion, stress, frustration" and isolation.
Eighteen months later the market has been repriced: Curl closed its bug-bounty programme, HackerOne paused its Internet Bug Bounty, and Elastic put a price on reading one report.
A timeline of closures
Curl ended its HackerOne programme on 31 January 2026, after seven years and 87 confirmed vulnerabilities. Daniel Stenberg named his goal as "remove the incentive for people to submit crap and non-well researched reports to us". In one sixteen-hour stretch that month the project received seven reports; none was a vulnerability.
On 27 March HackerOne's Internet Bug Bounty, which had funded fixes in open-source projects since 2013, stopped taking new submissions; AI-assisted discovery had outrun it.
On 21 April the company launched h1 Validation and published its figures: submissions up 76% year over year, a record 46,947 in March, and remediation capacity up only 19%. May's "Finding Fast, Fixing Slow" named the asymmetry: remediating a single issue got about 80% faster while vulnerabilities resolved per month fell 46%. The backlog of validated but unresolved findings grew more than 21 times, and the resolution rate for criticals dropped from over 83% to under 40%.
On 4 August Elastic put a price on intake: its programme took more than 1,390 reports in the first half of 2026, more than 2024 and 2025 combined, with about 70% rejected at analysis. Triage costs roughly $0.50 to $1.15 to analyse and up to $4.90 to reproduce, around $2 on average. Language models, Elastic wrote, made vulnerability reports trivially cheap to generate.
The same researchers
The flood is not coming from a separate population. HackerOne's ninth Hacker-Powered Security Report found 70% of researchers already using AI in their workflow. What separates a paid report from noise is not the model but whether a human verified the reproduction and the root cause before pressing submit.
Discovery is cheap, triage is not
A bounty pays for discovery; nobody pays for triage or for the fix, and those costs are absorbed by the programme and the maintainer. That is why programmes pause while valid findings keep rising. For scale, NIST published about 50,000 CVEs in 2025, and one small vendor, Screenly, reported 331 submissions in six months, of which 39 were real.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.