Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google paused its open-source bug bounty until 2027 after a surge of invalid AI-generated reports.
Google paused its Open Source Software Vulnerability Rewards Program on October 1 after a significant rise in automated submissions, the vast majority of which were invalid. The company said engineers and open-source maintainers were overwhelmed by reports that failed validation or contained hallucinations. Google said it will provide an update in the first quarter of 2027 and pointed researchers to its other bug bounty programs in the meantime.
- Open Source Software Vulnerability Rewards Program paused on October 1.
- Google blamed a surge of automated submissions, most of them invalid.
- Maintainers were overwhelmed by hallucinated or non-valid reports.
- An update is promised in Q1 2027; other Google bounty programs continue.
Full article157 words · extracted from techcrunch.com · click to collapse
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
Text extracted automatically; images, tables and formatting may be missing. Original: https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/