Hallucinated vulnerabilities
Direct answerConfident, plausible findings that do not reproduce. The curl project ended its bug bounty on 31 January 2026 after confirmed-report rates fell below five percent.
In more detail
Hallucinated findings are the cost side of AI auditing. The mitigations that work are execution-based validation (sandboxed exploits, fuzzing oracles), a second validating agent, and a human who reproduces before reporting.
Related terms
False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration
Getting help
Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.