Building Is Solved. Selling Is the New Hard Problem.
What a month of silence at curl taught me about the one problem AI didn't solve.
Hi friends,
Greetings from Wrocław.
Quick context for new readers: I’m a Staff Engineer shipping loyalty systems by day. By night, usually the 20:30 to 22:00 window after kids are asleep, I build my own products in public. This newsletter documents that experiment with real numbers, including the ugly ones.
This week, one of the most respected engineers in open source did something remarkable. He turned the internet off.
And why am I the one writing about it? Because I just finished my own summer of bliss: 11 weeks offline.
1. THE SUMMER OF BLISS**
Daniel Stenberg has maintained curl for decades. It runs on billions of devices. If anyone has earned the right to be listened to, it’s him.
This month, he stopped listening.
From July 1 to August 2, 2026, curl is not accepting any vulnerability reports. Not through HackerOne, not through email. Stenberg calls it the “summer of bliss.“ (source: Cybernews, BleepingComputer, July 2026)
The reason is a flood of AI generated security reports. The numbers tell the story better than any rant could:
curl’s bug bounty paid over $100,000 across 87 confirmed vulnerabilities before shutting down on January 31, 2026.
Historically, more than 15% of incoming reports were valid.
By 2025, that rate fell below 5%.
Roughly 20% of all submissions were AI slop.
And here’s the nuance that makes this story worth your time: Stenberg acknowledged that AI report quality improved over time, and AI ultimately contributed to around 50 real bug fixes in curl. The tool was never the villain.
AI made producing a report nearly free, while evaluating a report stayed expensive, because evaluation requires a human with judgment. When output becomes infinite, attention becomes the bottleneck.
And the big problem is, that attention span is dropping down tremendously.
Think about it for a minute.
2. THE COMMUNITY SAYS IT OUT LOUD**
The same week curl went quiet, the most trending conversation on Indie Hackers was a thread titled “The hardest part isn’t building anymore.” It has 110 comments for the time I’m writing this.
The thesis: with AI, shipping is easy. The hard part is choosing the right problem, finding demand, and getting users.
Two lines from that conversation got me:
“The hard part shifted from building to choosing the right conversation.”
“building feels productive, but it often delays the harder question: where is the real demand?”
That second one hurts, because building does feel productive. You end the evening with commits, with a working feature, with something to show. Asking “where is the real demand” ends the evening with an uncomfortable open question.
The curl story and the Indie Hackers thread are the same story at different scales. AI collapsed the cost of output, but did not reduce the cost of earning attention and trust.
Every solo dev’s real competition is no longer “can I build it” but “can I get a stranger to care.”
3. MY OWN UNCOMFORTABLE NUMBERS**
I can build. Fourteen years of professional engineering, event driven systems, data pipelines, the whole toolbox. This year I shipped automateideasai.com, a live product with working payments. I built and launched the Ship & Sell Starter Kit, a complete system for going from built to shipped in 14 days.
And selling is still the part I’m figuring out. In public, with real numbers, every week, in this newsletter.
Ship & Sell = 0x sales
AutomateIdeasAi = 1x sale
Substack Subscribers = 54
X followers: 1011
Hanami Mastery newsletter: 152
Udemy students: 3000+
Sharing this is uncomfortable but I think it’s important.. The only thing that gained somewhat good results in attention numbers is the one that had own distribution: Udemy. So I’m figuring it out.
The most valuable thing in an AI saturated feed is a verifiably human person figuring it out in public. I’d rather be the honest test case than another guru with a screenshot
4. FINDING DEMAND BEFORE WRITING CODE**
So what do I do differently now? Here’s the system I’ve committed to, stated publicly so you can hold me to it.
Rule 1: Conversations before code.
Before building anything new, I find where the target user already complains. I do not run sruveys, because my audience is near 0. I look for threads that exist without me. If I can’t find repeated, unprompted complaints about the problem, the problem is not painful enough to pay for.
Rule 2: One channel, done properly.
The research I ran last week was blunt about this: for a small newsletter, the growth engine is consistent Notes plus one strong essay, not being everywhere at once. Scattered presence is the distribution version of 47 half finished projects.
Rule 3: Sell before polishing.
The Ship & Sell Kit taught me this the honest way. A landing page and a payment link validate more in a week than a roadmap validates in a quarter. If nobody clicks buy on the ugly version, nobody will click buy on the pretty one.
What’s next
I think it’ll be even more meaningful to build things that are HARD to be reproduced quickly with AI help, becuase if disproportion becomes so vast, even less people than now will be willing to jump into this train.
The revolutionary part of 2026 already happened**, and it happened to everyone equally: building got easy. What’s left is the unglamorous, human, slow part. Attention. Trust. Demand.
The maintainer of curl bought himself a month of silence. Honestly, he earned it.
The rest of us have to earn the opposite: a reason to be heard.
Talk next week,
Seb
P.S. If “shipped but not sold” describes your project, the Ship & Sell Starter Kit is exactly this problem turned into a 14 day checklist. It’s $29 at the founding price. As I keep adding value to it, the price moves to $79 and then $129, and early buyers keep every future update at the price they paid. Details check out here!







