Skip to content

Person

Daniel Stenberg

curl maintainer who shut down the project's bug bounty program on February 1, 2026 because AI-generated reports overwhelmed maintainers.

Current stories

securityConfirmed6 publishers

Anthropic sends unreviewed AI bug reports with proofs of concept to open source maintainers

Anthropic expects more than 90% of the unreviewed vulnerability reports its new OSS Scanner sends to open source maintainers to be real. Opt-in projects get findings faster and take on the work of catching the errors, such as wrong severity ratings.

Perspective Coverage

6 publishers
Builder
Builder 52%
Operator
Operator 37%
Investor
Investor 11%

Reality

Evidence60
Adoption35
Hype gap+15
Incentives70
Confidence62
buildConfirmed14 publishers

Google halts product reports to its open-source bug bounty after a flood of invalid AI submissions

Google stopped taking product vulnerability reports for its open-source bug bounty on October 1 after a flood of invalid AI-generated submissions. Any team that takes outside security reports faces the same imbalance, with reports now cheap to write and as costly as ever to check.

Perspective Coverage

15 publishers
Builder
Builder 41%
Operator
Operator 50%
Investor
Investor 9%

Reality

Evidence76
Adoption55
Hype gap+20
Incentives35
Confidence72