Google pauses its open source bug bounty over a surge in AI submissions

Google pauses its open source bug bounty over a surge in AI submissions

Google has paused its open source bug bounty program until next year, blaming a "significant rise" in AI submissions. The program is the Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company's open source software.

In posts on X and on the program website, Google said the program was paused as of October 1, and promised "an update" in the first quarter of 2027. The company explained the decision this way: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

TechCrunch relays an account from Tom's Hardware, according to which Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.

TechCrunch links the move to an earlier warning. Last year it reported that cybersecurity experts were cautioning that AI slop posed a serious risk to bug bounty programs, and it says that appears to be the issue now confronting Google's program.

In the meantime, participants are encouraged to consider Google's other bug bounty programs.

Key facts

  • Google paused its Open Source Software Vulnerability Rewards Program as of October 1.
  • Google blames a significant rise in automated submissions, "the vast majority of which are not valid".
  • Per Tom's Hardware, as relayed by TechCrunch, engineers and maintainers were overwhelmed by invalid or hallucinated reports.
  • Google promises an update in the first quarter of 2027.
  • Participants are encouraged to consider Google's other bug bounty programs meanwhile.

Why it matters

Bug bounties pay outside researchers to find security holes, and this one covers Google's open source software. TechCrunch notes that experts warned last year that AI slop posed a serious risk to such programs. Google's pause is that concern showing up in a live program, with the company itself saying most of the automated submissions it received were not valid.

Who it affects

Researchers who were rewarded for finding vulnerabilities in Google's open source software can no longer submit to the program for now. Google engineers and open source maintainers are the people said to have been overwhelmed by invalid or hallucinated reports. Participants are pointed to Google's other bug bounty programs.

How to use it

Nothing can be submitted to this program while the pause lasts. Google encourages participants to consider its other bug bounty programs in the meantime. The source does not say which ones are meant, so check Google's program website and its posts on X for details and for the promised update.

How solid is it

The core facts come from Google itself, in posts on X and on the program website, plus a direct statement from the company. The account of engineers and maintainers being overwhelmed by invalid or hallucination-filled reports is attributed to Tom's Hardware and relayed by TechCrunch. The source gives no figures for how many submissions arrived or what share was invalid beyond "the vast majority".

Risks and caveats

The pause is described as a pause, not a cancellation. It is not stated whether Google will resume, change or end the program; only an update in the first quarter of 2027 is promised. The source does not say whether submissions already received will still be reviewed or paid, and it does not say which AI tools produced the submissions. Gaps in the program for open source software during the pause are not addressed in the source.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid”

— Google, in a statement on its Open Source Software Vulnerability Rewards Program