agentsastLast reviewed 2026-09-13

Hallucinated vulnerabilities

Direct answerConfident, plausible findings that do not reproduce. The curl project ended its bug bounty on 31 January 2026 after confirmed-report rates fell below five percent.

In more detail

Hallucinated findings are the cost side of AI auditing. The mitigations that work are execution-based validation (sandboxed exploits, fuzzing oracles), a second validating agent, and a human who reproduces before reporting.

False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.