AI is overwhelming bug bounty programs with convincing but useless reports — and some major projects are shutting theirs down entirely. In this week’s news brief, we break down the economics behind “AI slop,” why curl pulled the plug on its program, and what this means for ethical hackers. Then we revisit OpenClaw, where security researchers are shifting from criticism to collaboration — and even VirusTotal is stepping in. Is AI breaking security… or reshaping it? Sources mentioned: Daniel Stenberg (cURL) — The end of the curl bug-bounty (Jan 26, 2026) https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/ GitHub — cURL Statement on Bug Bounty https://github.com/curl/curl/pull/20312 Daniel Stenberg (cURL) — The I in LLM stands for Intelligence (Jan 2, 2024) https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ The Register — AI-assisted bug reports make developers question their existence (Jan 4, 2024) https://www.theregister.com/2024/01/04/aiassisted_bug_reports_make_developers/ Django Project — Recent trends in security team reports (Feb 4, 2026) https://www.djangoproject.com/weblog/2026/feb/04/recent-trends-security-team/ Node.js — HackerOne Signal Requirement (Jan 21, 2026) https://nodejs.org/en/blog/announcements/hackerone-signal-requirement HackerOne Docs — Signal Requirements https://docs.hackerone.com/en/articles/8505319-signal-requirements TechCrunch — AI slop and fake reports are exhausting some security bug bounties (Jul 24, 2025) https://techcrunch.com/2025/07/24/ai-slop-and-fake-reports-are-exhausting-some-security-bug-bounties/ CycloneDX — commit removing bug bounty mention https://github.com/CycloneDX/cyclonedx-rust-cargo/commit/93b19cb4ac96d1b8f51647df2b89ec4359becae1 Seth Larson — Slop security reports https://sethmlarson.dev/slop-security-reports/ Bugcrowd — Hacker Opinion: How Lazy Hacking Killed Curl’s Bug Bounty https://www.bugcrowd.com/blog/hacker-opinion-piece-how-lazy-hacking-killed-curls-bu