Google halts bug bounty program after flood of invalid AI submissions overwhelms security team

6 Sources

Share

Google suspended its Open Source Software Vulnerability Rewards Program on October 1, citing a surge in automated AI submissions that were largely invalid or contained hallucinations. The pause will last until at least Q1 2027 as the company works to address the overwhelming volume of AI-generated bug reports that have made the program unmanageable for engineers and maintainers.

Google Suspends Bug Bounty Program Amid AI Report Flood

Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) effective October 1, 2026, after being overwhelmed by a surge of invalid AI submissions

1

2

. The program, which offered rewards ranging from $100 to $31,337 for discovering vulnerabilities in open source software like Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, will remain suspended until at least Q1 2027

2

. Google engineers and open source maintainers found themselves buried under automated submissions that were either invalid or contained hallucinations, making the program unmanageable

1

.

Source: BleepingComputer

Source: BleepingComputer

Why AI-Generated Bug Reports Became Unmanageable

The pause addresses a critical problem in cybersecurity: AI-generated content in cybersecurity programs is flooding vulnerability reporting channels with low-quality submissions

4

. While AI tools like Mythos and GPT-5.6-Cyber have enabled companies to discover vulnerabilities at unprecedented speed, they often produce flawed or incomplete findings

3

. Security researchers using simple prompts with minimal analysis and little human oversight generate discoveries that are incorrect, unsubstantiated, or outright hallucinated

3

. Research from 1Password's Off-by-1 Labs found that 49.3% of AI-generated patches failed to fix at least one existing exploit path, while 2.3% introduced new security issues

3

. Missing context emerged as the primary challenge preventing AI from producing reliable security research.

Source: TechRadar

Source: TechRadar

Impact on Google's Vulnerability Rewards Ecosystem

The suspension affects only product vulnerability submissions under the Google bug bounty program's OSS VRP track

2

. Supply chain reports through OSS VRP remain unaffected, as do submissions made before October 1

4

. Researchers can still pursue the Google Patch Rewards Program, which offers bounties up to $15,000 for high-impact fixes, or report vulnerabilities affecting Google Cloud products through the Cloud VRP

2

. Since launching its first vulnerability rewards program in 2010, Google has awarded over $81.6 million to thousands of security researchers

2

. In 2025 alone, the company distributed a record-breaking $17.1 million to more than 700 researchers, marking a 40% increase from the $12 million awarded in 2024

2

.

Industry-Wide Pattern of AI Slop Reports

Google joins a growing list of organizations struggling with AI slop reports in their security programs

3

. In January 2026, curl maintainers ended their HackerOne bug bounty program after being overwhelmed by AI-generated vulnerability reports with no real substance

2

4

. Intel quietly removed all financial rewards from its Intigriti bug bounty program in mid-September, which previously offered up to $100,000 for security flaws

2

4

. Linux kernel maintainer Linus Torvalds described the security mailing list as "almost entirely unmanageable" in May, noting that researchers using AI flooded it with duplicate findings

3

. Microsoft warned that AI tools surfacing more vulnerabilities would increase operational demands across the software industry

2

. The company's patch volume demonstrates this trend: Microsoft addressed 79 flaws in March 2026, then 167 in April after deploying Mythos, escalating to 966 patches by September

3

.

Source: TechCrunch

Source: TechCrunch

What Security Researchers Should Watch

Google's decision signals a broader reckoning in how the cybersecurity community approaches automated vulnerability discovery and reporting. The company plans to reformat the OSS VRP to handle automated submissions more effectively, though specific changes remain unclear until the Q1 2027 update

2

. Security research programs will likely implement stricter validation requirements or human verification steps to filter invalid AI reports. Organizations may adopt tiered submission systems that prioritize reports demonstrating genuine analysis over automated findings. The pause raises questions about whether other major bug bounty programs will follow suit if AI-generated vulnerability reports continue degrading signal-to-noise ratios. Researchers relying on AI tools for vulnerability discovery must provide proper context and conduct thorough validation before submission. The industry faces a critical decision point: harness AI's speed for legitimate security research while preventing automated submissions from overwhelming the very programs designed to improve software security.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved