AI1 mins read

Google pauses open source bug bounty program after rise in AI submissions

Google has paused its Open Source Software Vulnerability Rewards Program after a significant rise in automated AI submissions, saying most were not valid.

What Google paused

Google has paused its Open Source Software Vulnerability Rewards Program, which rewarded researchers for finding vulnerabilities in the company’s open source software. The pause took effect October 1, and Google said it plans to provide an update in the first quarter of 2027.

The company attributed the move to a “significant rise” in automated submissions. Google said the vast majority of those submissions were not valid.

Why AI-generated reports are a problem

TechCrunch frames the pause as part of a broader strain on bug bounty programs caused by low-quality AI submissions. The article says cybersecurity experts had previously warned that AI slop and fake reports posed a serious risk to these programs.

According to the report, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. The takeaway for security teams is clear: submission volume is less useful when triage quality collapses.

What researchers should do next

Google encouraged participants to consider its other bug bounty programs while the open source program is paused. Researchers should verify findings carefully, avoid automated low-confidence reports, and focus on reproducible vulnerabilities.

For maintainers, the pause highlights the need for clearer submission standards and stronger filtering around automated reports. AI can speed up security work, but unverified output can also create expensive noise for teams already handling complex vulnerability queues.

Discover More

    Nine suitcases full of gold bars, and two suitcases full of 100-dollar cash bills, as a photo taken from above.
    CIA Officer Fraud Plea

    David J. Rush admitted to wire fraud tied to a fake top secret government program.

    CIAGovernment Fraud
    Healthleap founders Jemima and Josiah Meyer
    Healthleap raises $38M

    The healthtech startup is scaling AI that flags hospital patients for closer review without making diagnoses.

    HealthTechAI