Replying to
@sarah@phpc.social @pollita@phpc.social Here's Daniel's initial blog post on the matter: https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
In the hands of experts, proprietary LLM-assisted security analysis caught 50 bugs/vulnerabilities in Curl: https://daniel.haxx.se/blog/2025/10/10/a-new-breed-of-analyzers/
But commercially-available LLMs make it easy for clueless grifters to submit HackerOne reports, so they had to shut down the whole thing.
