Google pauses its open source bug bounty over AI slop
Google has paused its Open Source Software Vulnerability Rewards Program, blaming a surge of automated submissions that were mostly not valid.

Google has switched off its bug bounty for open source software. The company paused its Open Source Software Vulnerability Rewards Program (OSS VRP) on 1 October, and it is not taking new reports until it has something to say about what happens next.
The reason is not a shortage of bugs. In a notice carried on the programme's own rules page and on the @GoogleVRP account on X, the company blamed “a significant rise in automated submissions, the vast majority of which are not valid”. The slop has arrived, and the people who read the reports have had enough of it.
What Google actually said
The wording is short and careful. The pause took effect on 1 October, the company says, and participants are pointed toward Google's other bug bounty programmes in the meantime. No return date has been given, and the only commitment is an update in the first quarter of 2027. That is a four-month hole in a scheme that paid researchers for finding flaws in Google's open source code.
The open source programme was one of the more respected routes into Google's security work, and it is now the first casualty of a problem the industry has seen coming. Tom's Hardware reports that engineers and maintainers were overwhelmed by reports that were invalid, or that contained invented detail — the fingerprints of an AI tool asked to produce a finding rather than discover one.
Why one paused programme matters
A bug bounty is only as good as its triage. Every invalid report still costs a human the time to read it, try to reproduce it and rule it out, and that cost falls hardest on the maintainers of small open source projects who joined the scheme looking for help rather than homework. When the volume of junk grows faster than the volume of real findings, the programme stops paying for bugs and starts consuming the people who fix them.
It is not a Google-only problem, either. TechCrunch reported in 2025 that security researchers were already warning that AI-generated reports could exhaust bug bounty programmes, and the same arithmetic now applies to every project that accepts reports from strangers.
Our opinion
Pausing the programme is the honest call, and it is a better look than letting reports rot in a queue nobody reads. It is also an admission that the tooling for sorting real vulnerabilities from confident nonsense has not kept pace with the tooling generating the nonsense. In the gap, genuine flaws in code that half the internet runs go unreported.
The fix is not to stop paying for bugs; it is to make the cheap, automated, almost-plausible report expensive to send. Proof-of-concept requirements, reputation systems and rate limits are unglamorous work, but they are the difference between a programme that finds things and a mailbox that fills itself. Google has until the end of March to show it can build one.