STUPID-2026-0037
AI 'slop' vulnerability reports flooded curl until it killed its bug bounty
Instruction given
Generate a security vulnerability report to submit to curl's bug bounty.
Expected behavior
Only report real, reproducible vulnerabilities in code that actually exists.
Actual behavior
LLMs produced long, confident, fabricated vulnerability reports — one 'HTTP/3 stream dependency cycle exploit' came complete with GDB sessions and register dumps referencing a function that does not exist in curl. Roughly one in five 2025 submissions was outright AI slop.
Damage
The confirmed-vulnerability rate fell from above 15% to below 5%. Each bogus report still ate hours from curl's seven-person volunteer security team. Maintainer Daniel Stenberg ended the curl bug bounty entirely at the end of January 2026 to remove the payout incentive.
Classification
- Agent
- Multiple LLMs
- Failure mode
- Hallucination
- Root cause
- Confidence Miscalibration
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.