Google has paused its open source bug bounty program until next year, saying the decision is due to a "significant rise" in automated submissions, the vast majority of which are not valid.
The Open Source Software Vulnerability Rewards Program, which pays researchers for finding vulnerabilities in Google's open source software, was suspended as of October 1. The company said it will provide "an update" in the first quarter of 2027.
According to Tom's Hardware, Google engineers and open source maintainers had been overwhelmed by reports that were invalid or contained hallucinations. In a statement, Google said: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
The move comes a year after cybersecurity experts warned that AI-generated "slop" posed a serious risk to bug bounty programs. Researchers had raised concerns that automated tools could generate large volumes of plausible-looking but fraudulent vulnerability reports, draining the time of the humans paid to vet them.
In the meantime, Google is encouraging participants to consider its other bug bounty programs.