Google pauses an open-source bug bounty over AI-generated reports
A flood of invalid automated submissions overwhelmed maintainers, freezing the program until at least early 2027.

Google has stopped paying outsiders to find security flaws in open-source software. The program drowned in automated reports that mostly turned out to be worthless. TechCrunch reported the freeze on Sunday, October 4, and said the pause to Google's Open Source Software Vulnerability Rewards Program took effect on October 1.
The reason, in Google's own words, was the machines. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said in a statement. According to TechCrunch, engineers and open-source maintainers had been buried under invalid reports full of AI hallucinations, plausible-looking vulnerabilities that do not actually exist.
Bug bounty programs run on trust and attention. Researchers submit findings, and someone on the other end has to read each one closely enough to tell a real flaw from a false alarm. When a large share of the incoming reports are confident, well-formatted and wrong, that triage work stops scaling. The humans doing it drown.
Google did not say how many submissions it received or how many it rejected, and TechCrunch's article gave no figures. The company said it will provide an update on the program during the first quarter of 2027. Until then, according to the report, participants are being pointed toward Google's other bug bounty programs to submit their findings.
The problem was flagged well before it arrived. TechCrunch noted that in July 2025 it had reported warnings from cybersecurity experts that AI-generated content posed serious risks to bug bounty programs, and said Google's freeze shows that warning has now come true.
TechCrunch's Anthony Ha summed up the moment in a single line: "AI slop seems to be overwhelming bug bounty programs." The freeze is a small, concrete example of a bigger cost. A system built to accept contributions from anyone now has to defend itself against machines that can produce them endlessly.
Sources
- Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions · TechCrunch, AI