Google Paused Its Open-Source Bug Bounty Because AI Wrote Too Many Fake Bug Reports
October 5, 2026 — Google froze one of its flagship bug bounty programs after it was swamped with AI-generated vulnerability reports that mostly describe bugs that don’t exist. The hunters’ own tools became the flood.
What happened
Google has temporarily stopped accepting product vulnerability submissions through its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company said the pause stems from “a significant rise in automated submissions, the vast majority of which are not valid.” Google promised an update on the program’s future in Q1 2027.
The details
The OSS VRP, launched in August 2022, pays outside researchers for responsibly disclosing flaws in Google-maintained open-source projects — including Golang, Angular, Bazel, Protocol Buffers, and Fuchsia — plus critical third-party dependencies. Rewards run from $100 to $31,337 per report.
Not everything is frozen: supply-chain vulnerability reports remain in scope, outstanding reports filed before October 1 will still be handled, and researchers can still submit fixes through the Patch Rewards Program (up to $15,000 for high-impact fixes) or report Cloud product vulnerabilities through the Cloud VRP. This is a big program to stall: since its first bounty program in 2010, Google has paid over $81.6 million to researchers, including a record $17.1 million to more than 700 researchers in 2025.
The problem is triage. AI-generated reports can read like expert work — code snippets, attack paths, confident severity ratings — while describing invented exploit paths and functions that aren’t actually reachable. Every one still costs a security engineer time to disprove. Google isn’t alone here: in January, the maintainer of the curl utility ended its HackerOne bounty after the same flood of low-quality AI-generated reports overwhelmed a small team.
Why it matters
This is AI’s trust problem in miniature. The same models that are finding real vulnerabilities at superhuman scale — Google and Microsoft both report discovering far more flaws with AI assistance — are also drowning the human systems that validate them. A bug bounty runs on a simple bargain: someone does the work, someone else verifies it, and the finder gets paid. Automated submissions break the bargain’s economics by making verification free for the sender and expensive for the receiver. Until report-filtering gets as good as report-generation, expect more programs to follow Google’s lead — and expect the security work that survives to carry higher evidence requirements.
FAQ
Can I still report open-source vulnerabilities to Google?
Yes, in some cases: supply-chain reports are still accepted under the OSS VRP, and security patches can go through the Patch Rewards Program (up to $15,000). Product vulnerability submissions are paused until further notice.
When will the program reopen?
Google said it is reworking the OSS VRP to handle automated submissions and will provide an update in Q1 2027. No firm reopening date was given.
Is Google the first to do this?
No. The curl project ended its HackerOne bug bounty in January 2026 after being overwhelmed by AI-generated reports, and Intel removed financial rewards from its Intigriti program in September.
Sources: TechCrunch, BleepingComputer, Malwarebytes, Google Bug Hunters.

