Google Pauses Open Source Bug Bounty Over AI Spam

Original: Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Why This Matters

AI spam is now actively disrupting security infrastructure, not just content platforms.

Google suspended its Open Source Software Vulnerability Rewards Program on Oct. 1, 2026, citing a surge in AI-generated, largely invalid bug reports, with no restart planned before Q1 2027.

Google has frozen its Open Source Software Vulnerability Rewards Program (OSS-VRP), which pays researchers for finding vulnerabilities in the company's open source projects. The pause, effective October 1, 2026, was announced via posts on X and the program's official website. Google blamed "a significant rise in automated submissions, the vast majority of which are not valid."

According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by AI-generated reports riddled with hallucinations and invalid findings. The company says it will provide an update in Q1 2027. In the meantime, participants are directed to Google's other active bug bounty programs.

The development lands roughly a year after cybersecurity experts warned TechCrunch that AI-generated "slop" posed a serious risk to bug bounty programs industry-wide. That prediction has now materialized at one of the largest targets in open source security.

Source

techcrunch.com — Read original →