12 min read
curl's Bug Bounty Is Dead. The Autopsy Tells Two Very Different AI Stories.
AI slop killed curl's seven-year bug bounty program. Then AI-powered research found 170 real bugs in the same codebase. The difference was not the technology. It was the methodology. What the curl saga teaches every security team about the gap between AI noise and AI discovery.