The general trend so far in 2025 has been way more AI slop than ever before (about 20% of all submissions) as we have averaged in about two security report submissions per week. In early July, about 5% of the submissions in 2025 had turned out to be genuine vulnerabilities. The valid-rate has decreased significantly compared to previous years. [...] Dropping the monetary reward part would make it much less interesting for the general populace to do random AI queries in desperate attempts to report something that could generate income.
Curated from daniel.haxx.se · 14 July 2025 →
curl is one of the most widely deployed pieces of software in the world, and its security team is a handful of volunteers. Daniel Stenberg, who wrote it, has been publishing the arithmetic of what generative AI has done to their inbox since January 2024: reports that read as competent security research, cite real-looking functions and describe vulnerabilities that do not exist, each of which still has to be read by a human before it can be dismissed. By July 2025 a fifth of all submissions were slop and one in twenty was a real vulnerability. The curl bug bounty had paid out more than 90,000 US dollars across 81 genuine findings since 2019. Stenberg spent the rest of the year weighing whether the money was now what was drawing the noise.