Google suspends open-source bug bounty program after AI-generated report deluge

OSS VRP paused as automated submissions overwhelm review process

By LineZotpaper
Published
Read Time2 min
Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded with low-quality, AI-generated security reports. The company announced the pause on social media, citing a significant rise in automated submissions, the vast majority of which are not valid.

The OSS VRP, launched in August 2022, incentivised researchers to disclose security flaws in Google-maintained open-source projects such as Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies. Rewards ranged from $100 to $31,337.

Google stated on X that it is temporarily not accepting OSS VRP product vulnerability submissions. The pause does not affect supply chain reports or any outstanding submissions made before October 1, 2026. Researchers can still submit security patches through the Google Patch Rewards Program, which offers bounties of up to $15,000, and report vulnerabilities in Google Cloud open-source repositories via the Cloud VRP.

The company said it is working to address the automated submission issues and will provide an update in Q1 2027.

Google is not the first to shut down a bug bounty program because of poor-quality AI-generated reports. In January 2026, the maintainer of the curl utility ended its bug bounty program after a similar flood of AI-generated reports.

Since launching its first Vulnerability Rewards Program in 2010, Google has paid over $81.6 million to thousands of security researchers. In 2025, it awarded a record $17.1 million to more than 700 researchers, a 40% increase from 2024.

§

Analysis

Why This Matters

  • Security researchers who rely on bug bounty income lose a key avenue for reporting vulnerabilities in widely used open-source projects
  • The flood of AI-generated reports threatens the viability of volunteer-moderated vulnerability disclosure programs across the industry
  • Google's pause signals that automated spam is a growing systemic problem that may require new verification methods

Background

Bug bounty programs reward independent security researchers for responsibly disclosing vulnerabilities. Google's VRP has been among the most generous, paying over $81 million since 2010. The OSS VRP specifically targeted open-source software maintained by Google, aiming to improve supply chain security. AI-generated submissions have grown rapidly, producing low-quality reports that waste reviewer time. Program maintainers have struggled to distinguish genuine findings from automated noise.

Key Perspectives

Google: The company says the pause is necessary due to a surge in invalid automated submissions. It is working on reforms and promises an update in early 2027. It points researchers to other reward programs that remain open. Security researchers: Legitimate researchers lose access to a significant reward program for open-source vulnerabilities. Those whose submissions are still outstanding may face delays in processing. Program maintainers: The curl project's earlier experience shows this is an industry-wide challenge. Without better filtering, more programs may pause or close.

What to Watch

  • Whether Google's OSS VRP reforms introduce submission verification, such as requiring human-written summaries or proof-of-concept demonstrations
  • Adoption of AI-resistant submission systems by other major bug bounty programs
  • Potential rise in unreported vulnerabilities if researchers see fewer financial incentives

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.