Google pauses open source bug bounty over AI spam

Google put its open source vulnerability rewards program on hold after a surge in automated reports, saying most submissions were not valid.
Google has paused its open source bug bounty program after what it called a “significant rise” in automated submissions. The suspension affects the company’s Open Source Software Vulnerability Rewards Program, which pays researchers for finding flaws in Google’s open source software.
The move matters because bug bounty programs depend on detailed, credible reports. When too many submissions are low-quality or fabricated, they can bog down reviewers and make the whole system less useful for both researchers and maintainers. As IT-PUB News points out, Google says most of the recent automated submissions were not valid.
Google says invalid automated reports forced the pause
In posts on X and on the program website, Google said the pause took effect on October 1. The company said it plans to provide “an update” in the first quarter of 2027.
Google’s explanation was direct: the program saw a sharp increase in automated submissions, and “the vast majority” of them were not valid. The company did not say it was shutting the program down permanently — only that it is on hold for now.
The issue appears to be linked to AI-generated reports. Last year, TechCrunch reported that cybersecurity experts were warning that AI slop could become a serious problem for bug bounty programs. Google’s announcement suggests that concern has now reached one of its own reward schemes.
The program depends on verifiable security findings
The Open Source Software Vulnerability Rewards Program was set up to reward researchers who uncover security issues in Google’s open source software. That only works if people submit real findings that engineers and maintainers can verify and fix.
Once invalid reports start piling up, the process gets harder to manage. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were either invalid or contained hallucinations. Google did not use those exact words, but it did say the flood of automated submissions led to the pause.
That creates a problem beyond one Google program. Bug bounty systems are one way companies and open source projects encourage outside security research. If the review pipeline gets clogged with noisy submissions, legitimate researchers may be discouraged, and useful findings can become harder to spot among machine-generated clutter.
Google directs researchers to its other bounty programs
Google said participants should consider its other bug bounty programs in the meantime. The source text does not explain how those programs differ or whether they have run into the same pressure from automated submissions.
The pause also leaves a larger issue hanging over bug bounty programs. AI tools make it easier to produce reports at scale, and the source does not say whether Google plans to change its review process before reopening this one. What is clear is that Google sees the problem as serious enough to keep the program suspended while it works out its next step.