Google pauses open source bug bounty program amid flood of AI-generated reports
Google has temporarily halted its open source vulnerability rewards program after a sharp increase in AI-generated submissions, most of which were invalid. The program is not expected to resume before the first quarter of 2027.

Google has paused its Open Source Software Vulnerability Rewards Program, which rewards security researchers for identifying vulnerabilities in the company's open source software. The pause took effect on October 1, with Google promising an update in the first quarter of 2027.
The company cited a "significant rise" in automated submissions as the reason for the halt, stating that the vast majority of these reports were not valid.
Engineers overwhelmed by faulty reports
According to Tom's Hardware, Google engineers and open source maintainers had been overwhelmed by submissions that were invalid or contained AI hallucinations. The issue echoes warnings cybersecurity experts raised previously about so-called "AI slop" posing a serious risk to bug bounty programs generally.
Google announced the pause both on X and on the program's official website. In the meantime, the company is encouraging researchers to use its other available bug bounty programs until the open source program resumes.


