6 Sources
[1]
Google froze its open source bug bounty program due to a 'significant rise' in AI submissions
Blaming a "significant rise" in AI submissions, Google has paused its open source bug bounty program until next year. Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that's the issue confronting Google's
[2]
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. The company's OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google,
[3]
Google benches open source bug bounty program following 'significant rise' in AI submissions
* Google paused OSS bug bounty submissions after a surge of AI-generated, invalid reports * AI boosts vulnerability discovery but often produces flawed, incomplete, or hallucinatory findings * Rising AI-driven bounty spam has also overwhelmed curl maintainers and Linux security reviewers Google
[4]
Google pauses its open-source bug bounty program after a flood of AI slop reports
Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), citing a flood of low-quality, AI-generated reports that its team could no longer keep up with. The pause took effect on October 1 and will run until at least the first
[5]
Google pauses open-source bug bounty program over invalid AI reports
Google has paused its open-source software bug bounty program, citing a "significant rise" in automated AI-related submissions, most of which were invalid. The company said in posts on X and the program website that the pause took effect on October 1. It promised to provide "an update" in the
[6]
AI churns out bug reports faster than Google can verify them - MEDIANAMA
On October 1, Google paused its program that compensates external researchers for identifying security flaws in its open-source projects. TechCrunch reported that Google has paused its Open Source Software Vulnerability Reward Program (OSS VRP) due to a significant increase in automated
Share
Copy Link
Google suspended its Open Source Software Vulnerability Rewards Program on October 1, citing a surge in automated AI submissions that were largely invalid or contained hallucinations. The pause will last until at least Q1 2027 as the company works to address the overwhelming volume of AI-generated bug reports that have made the program unmanageable for engineers and maintainers.
Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) effective October 1, 2026, after being overwhelmed by a surge of invalid AI submissions
1
2
. The program, which offered rewards ranging from $100 to $31,337 for discovering vulnerabilities in open source software like Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, will remain suspended until at least Q1 20272
. Google engineers and open source maintainers found themselves buried under automated submissions that were either invalid or contained hallucinations, making the program unmanageable1
.
Source: BleepingComputer
The pause addresses a critical problem in cybersecurity: AI-generated content in cybersecurity programs is flooding vulnerability reporting channels with low-quality submissions
4
. While AI tools like Mythos and GPT-5.6-Cyber have enabled companies to discover vulnerabilities at unprecedented speed, they often produce flawed or incomplete findings3
. Security researchers using simple prompts with minimal analysis and little human oversight generate discoveries that are incorrect, unsubstantiated, or outright hallucinated3
. Research from 1Password's Off-by-1 Labs found that 49.3% of AI-generated patches failed to fix at least one existing exploit path, while 2.3% introduced new security issues3
. Missing context emerged as the primary challenge preventing AI from producing reliable security research.
Source: TechRadar
The suspension affects only product vulnerability submissions under the Google bug bounty program's OSS VRP track
2
. Supply chain reports through OSS VRP remain unaffected, as do submissions made before October 14
. Researchers can still pursue the Google Patch Rewards Program, which offers bounties up to $15,000 for high-impact fixes, or report vulnerabilities affecting Google Cloud products through the Cloud VRP2
. Since launching its first vulnerability rewards program in 2010, Google has awarded over $81.6 million to thousands of security researchers2
. In 2025 alone, the company distributed a record-breaking $17.1 million to more than 700 researchers, marking a 40% increase from the $12 million awarded in 20242
.Related Stories
Google joins a growing list of organizations struggling with AI slop reports in their security programs
3
. In January 2026, curl maintainers ended their HackerOne bug bounty program after being overwhelmed by AI-generated vulnerability reports with no real substance2
4
. Intel quietly removed all financial rewards from its Intigriti bug bounty program in mid-September, which previously offered up to $100,000 for security flaws2
4
. Linux kernel maintainer Linus Torvalds described the security mailing list as "almost entirely unmanageable" in May, noting that researchers using AI flooded it with duplicate findings3
. Microsoft warned that AI tools surfacing more vulnerabilities would increase operational demands across the software industry2
. The company's patch volume demonstrates this trend: Microsoft addressed 79 flaws in March 2026, then 167 in April after deploying Mythos, escalating to 966 patches by September3
.
Source: TechCrunch
Google's decision signals a broader reckoning in how the cybersecurity community approaches automated vulnerability discovery and reporting. The company plans to reformat the OSS VRP to handle automated submissions more effectively, though specific changes remain unclear until the Q1 2027 update
2
. Security research programs will likely implement stricter validation requirements or human verification steps to filter invalid AI reports. Organizations may adopt tiered submission systems that prioritize reports demonstrating genuine analysis over automated findings. The pause raises questions about whether other major bug bounty programs will follow suit if AI-generated vulnerability reports continue degrading signal-to-noise ratios. Researchers relying on AI tools for vulnerability discovery must provide proper context and conduct thorough validation before submission. The industry faces a critical decision point: harness AI's speed for legitimate security research while preventing automated submissions from overwhelming the very programs designed to improve software security.Summarized by
Navi
[1]
[2]
[3]
23 Jan 2026•Technology

02 Aug 2026•Technology

06 Oct 2025•Technology
