· via TechCrunch
Google pauses open source bug bounty program citing flood of invalid AI-generated reports
Google has frozen its open source vulnerability rewards program until at least early 2027, saying a surge of automated, largely invalid AI submissions has overwhelmed its reviewers.

Google has suspended its Open Source Software Vulnerability Rewards Program, and the company says the cause is a wave of automated, AI-generated submissions its security teams can no longer keep up with.
According to TechCrunch, the program — which rewarded researchers for finding security flaws in Google's open source projects — was paused as of October 1. Google announced the freeze in posts on X and on the program's website, and said it expects to share an update in the first quarter of 2027.
Why Google hit the pause button
Google attributed the suspension to a sharp increase in automated submissions, the overwhelming majority of which the company said were not valid. According to Tom's Hardware, the engineers and open source maintainers who review incoming reports were overwhelmed by submissions that were either outright invalid or contained hallucinations — fabricated details produced by the tools generating the reports.
The mechanics of the problem are simple. Generative AI makes it cheap and fast to produce plausible-looking vulnerability reports at scale, but every report still needs a human to verify it. When most of the automated output turns out to be junk, the cost of triage quickly outweighs the value of the occasional genuine finding, and the people doing that triage burn out.
A problem security experts predicted
TechCrunch notes that a year earlier it had reported on cybersecurity experts warning that AI-generated filler posed a serious risk to bug bounty programs. Google's pause looks like that warning playing out at one of the world's largest software companies.
Bug bounty programs rest on an implicit bargain: researchers invest skilled time hunting for real flaws, and organizations pay for results that hold up. Automated mass submission breaks that bargain by pushing the verification burden onto the operator while rarely delivering anything usable in return.
What happens to participants
For now, Google is directing participants toward its other bug bounty programs, which remain active. The company has not publicly detailed what changes, if any, it plans to make before reopening the open source track — only that more information will arrive in early 2027.
Why it matters
This is a concrete, measurable case of generative AI degrading an established security workflow rather than improving it. Vulnerability rewards programs depend on scarce human expertise on both sides — submitters who can find real bugs and reviewers who can confirm them — and Google choosing to pause rather than absorb the volume signals the problem outgrew its review capacity.
It also sets a precedent other program operators will watch closely. If AI-generated submissions can force a pause at Google, smaller programs with thinner triage resources face the same pressure with far less ability to absorb it. The questions operators now face — whether to pre-screen reports automatically, weight submissions by reputation, or tighten intake requirements — have become unavoidable design problems for anyone running a vulnerability disclosure program, not optional refinements.
- #security
- #bug-bounty
- #open-source
- #generative-ai