Google pauses open source bug bounty program, blaming flood of invalid AI submissions

Program suspended from October 1 until a promised update in early 2027 after maintainers were overwhelmed by automated reports

By LineZotpaper
Published
Read Time2 min
Sources2 outlets
Google has halted its Open Source Software Vulnerability Rewards Program, citing a "significant rise" in automated submissions that are largely invalid as engineers and open source maintainers struggled to process an influx of AI-generated reports.

Google has paused its open source bug bounty program until next year, saying the decision is due to a "significant rise" in automated submissions, the vast majority of which are not valid.

The Open Source Software Vulnerability Rewards Program, which pays researchers for finding vulnerabilities in Google's open source software, was suspended as of October 1. The company said it will provide "an update" in the first quarter of 2027.

According to Tom's Hardware, Google engineers and open source maintainers had been overwhelmed by reports that were invalid or contained hallucinations. In a statement, Google said: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

The move comes a year after cybersecurity experts warned that AI-generated "slop" posed a serious risk to bug bounty programs. Researchers had raised concerns that automated tools could generate large volumes of plausible-looking but fraudulent vulnerability reports, draining the time of the humans paid to vet them.

In the meantime, Google is encouraging participants to consider its other bug bounty programs.

§

Analysis

Why This Matters

  • Bug bounty programs rely on human reviewers to triage reports; a flood of automated, invalid submissions can crowd out genuine findings and delay security fixes.
  • The pause leaves a gap in reward-driven vulnerability research for Google's open source software, potentially slowing discovery of real bugs.
  • This is an early, concrete example of AI-generated content straining a security system, a problem other companies may soon face.

Background

Bug bounty programs pay security researchers to find and responsibly report vulnerabilities in software. In recent years, the rise of AI tools has enabled the mass production of technical-sounding reports that are often wrong or hallucinated. Cybersecurity experts began warning last year that this "AI slop" could exhaust the small teams who review submissions, a risk that now appears to have materialised at Google.

Key Perspectives

Google: Views the pause as a necessary response to an unsustainable volume of invalid automated submissions, and is pointing researchers toward its other bug bounty programs in the interim. Legitimate security researchers: May lose a valued channel for disclosing open source vulnerabilities and earning recognition or rewards, and could sit on findings until the program resumes. Cybersecurity critics: Will see this as confirmation that AI-generated noise is degrading the effectiveness of bug bounty systems, and may worry that other programs will follow suit or that real vulnerabilities will go unreported during the suspension.

What to Watch

  • Whether Google's first-quarter 2027 update tightens submission rules or adds automated screening for AI-generated reports.
  • Whether other major companies with open source bug bounty programs announce similar pauses.
  • Whether any serious open source vulnerabilities surface during the period the program is suspended.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.