Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google has paused its open source bug bounty program until 2027 due to an overwhelming influx of invalid and hallucinated reports generated by AI. The company aims to address the quality of submissions before resuming the program.
Why it matters
This highlights the growing challenge of 'AI slop' and automated spam undermining cybersecurity research and incentive programs.
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs . Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website , Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware , Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in