> Markdown version of [/videos/1796-don-t-insert-crazy-on-curl-and-ai-slop-daniel-stenberg](https://www.wearedevelopers.com/videos/1796-don-t-insert-crazy-on-curl-and-ai-slop-daniel-stenberg). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg Daniel Stenberg warns that AI-generated slop is destroying the open source ecosystem. Learn why the cURL creator finally killed his bug bounty program to stop the madness. - **Speakers:** Daniel Stenberg - **Event:** Coffee With Developers - **Published:** January 26, 2026 - **Duration:** 48:19 - **URL:** https://www.wearedevelopers.com/videos/1796-don-t-insert-crazy-on-curl-and-ai-slop-daniel-stenberg ## Summary Daniel Stenberg, the creator and maintainer of cURL, explains his recent decision to shut down the project's long-standing bug bounty program due to a massive influx of "AI slop." While the program successfully awarded bounties for 87 confirmed CVEs over the years, the rise of AI chatbots has led to an unsustainable volume of hallucinatory vulnerability reports. Opportunistic bounty hunters are now submitting AI-generated reports that falsely flag non-issues—such as made-up function names or expected behaviors—reducing the validity rate to less than one in twenty. This deluge of low-effort, highly verbose, and overly polite AI text has turned vulnerability triage into a full-time burden rather than a productive security measure. The conversation also dives into the broader existential threats AI poses to the open source ecosystem. Stenberg emphasizes a growing concern around "vibe coding," where developers rely entirely on AI to generate code based on scraped open source repositories. This breaks the traditional give-and-take of the open source model; developers are no longer returning bug reports, submitting pull requests, or adhering to proper licensing attributions. Without this human-in-the-loop feedback and basic community engagement, foundational projects risk losing the essential contributions that keep them secure and relevant. Despite these challenges, Stenberg remains focused on cURL's long-term sustainability through commercial support contracts with businesses that view the library as vital infrastructure. For users and security researchers alike, his ultimate advice acts as a guiding principle for API usage and AI reliance: "Don't insert crazy." Instead of intentionally bypassing documentation or blindly trusting confident, AI-generated output, engineers must prioritize human validation, critical thinking, and responsible integration. **Keywords:** curl, open source sustainability, bug bounty programs, ai-generated slop, hallucinated vulnerabilities, vibe coding, software security triage, commercial open source support, api misuse, automated code generation, open source licensing, internet connectivity libraries, hackerone platform, vulnerability reporting, maintainer burnout ## Chapters 1. **The ubiquity of the curl library in connected devices** (00:00) — Widespread reliance on foundational network libraries makes them a ubiquitous component in connected hardware. 1. **Shutting down the bug bounty program due to AI** (01:45) — Surges in automated chatbot submissions make evaluating generic security claims unsustainable for maintainers. 1. **Hallucinated vulnerabilities and automated bug hunting** (04:26) — Artificial intelligence tools frequently generate plausible but entirely fabricated vulnerability reports based on common language patterns. 1. **Moving vulnerability reporting to GitHub to deter bounty hunters** (09:08) — Shifting bug reports to platforms without direct payout incentives filters out low-effort automated submissions. 1. **Why standard pull requests face less AI spam** (13:55) — Automated continuous integration checks easily filter out non-functional code submissions before maintainer review. 1. **How AI code generation threatens open source feedback loops** (16:40) — Generating code without acknowledging external dependencies breaks the cycle of usage reporting and contributor recognition. 1. **Evaluating HackerOne metrics against fake vulnerability claims** (19:53) — Popular open source repositories face disproportionate amounts of fabricated security reports from users seeking monetary rewards or career advancement. 1. **Monetizing open source despite AI traffic interception** (25:08) — Alternative monetization strategies become necessary when generative AI tools intercept documentation traffic and reduce ad revenue. 1. **Commercial support contracts and maintainer succession planning** (28:44) — Providing long-term enterprise support requires established bus factor contingency plans for core maintainers. 1. **Code refactoring and the lifespan of software vulnerabilities** (33:39) — The latency between introducing a bug and its discovery complicates measuring the success of ongoing code refactoring efforts. 1. **Balancing library resilience with user responsibility for API inputs** (36:04) — Clear documentation must define the boundary between safe library usage and deliberate misuse by the caller. 1. **Supporting modern network protocols in foundational libraries** (37:55) — Foundational open source tools must continuously evolve to support modern web standards like HTTP/3. 1. **The necessity of human verification in security reporting** (41:00) — Submitting security claims requires independent logical reproduction rather than naive acceptance of automated tool outputs. 1. **Identifying AI-generated text patterns in issue tracking** (46:26) — Maintainers can identify generative AI submissions through distinct linguistic markers like excessive apologies and structured bullet points. ## Related Moments - [Handling the surge of AI-generated open-source code contributions](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) (from "Fighting the Next Wave of Cybercrime") - [The disproportionate impact of AI vulnerabilities on open source](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) (from "Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World") - [Navigating the impact of AI on open source maintenance](https://www.wearedevelopers.com/videos/100204-open-source-is-not-just-code-designing-communities-that-actually-scale) (from "Open Source Is Not Just Code: Designing Communities That Actually Scale") - [Managing AI generated code and slop in open source](https://www.wearedevelopers.com/videos/1788-wearedevelopers-live-you-don-t-need-javascript-modern-css-and-more) (from "WeAreDevelopers LIVE – You Don’t Need JavaScript, Modern CSS and More") - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") - [Navigating security risks in AI-assisted open source contributions](https://www.wearedevelopers.com/videos/100031-building-on-open-source-the-new-product-playbook) (from "Building on Open Source: The New Product Playbook") ## Related Articles - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [Dev Digest 116 - WWWAI?](https://www.wearedevelopers.com/magazine/449-dev-digest-116-wwwai) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Principal Product Manager, Agent Platform](https://www.wearedevelopers.com/jobs/ext/277541-principal-product-manager-agent-platform) at **GitHub** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio**