Google pauses open source bug bounty program due to surge in AI-generated submissions
Quick Look
Google has paused its Open Source Software Vulnerability Rewards Program as of October 1 due to a significant rise in invalid AI-generated submissions, with plans to provide an update in Q1 2027, while directing participants to other bounty programs.
AI-generated summary
Why It Matters
Google's Open Source Software Vulnerability Rewards Program previously rewarded researchers for finding vulnerabilities in the company's open source software, but has been overwhelmed by invalid AI-generated submissions.
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.
In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
What to Watch
AI outlook — possibilities, not facts
Google will relaunch its open source bug bounty program with improved AI detection mechanisms
Likely · Within months
Open Questions
- How will Google detect and filter AI-generated submissions in the future?
- What specific changes will be made to the bug bounty program before its relaunch?
- How many invalid submissions were received prior to the pause?







