NEWS

Google pauses open source bug bounty program after surge in AI-generated reports

The Open Source Software Vulnerability Rewards Program has been on hold since October 1: the company says most of the automated reports it received have no validity at all.

What happened

Google paused, starting October 1, 2026, its Open Source Software Vulnerability Rewards Program (OSS VRP), the bug bounty program aimed at security flaws in open source projects the company maintains or uses. The announcement was made in posts on X and on the program's official page, as reported by TechCrunch. The company has promised an update on the program's future only in the first quarter of 2027.

The justification is straightforward: a disproportionate volume of automated submissions, most of them invalid.

This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.

Google, in a statement on X and on the program's website

According to TechCrunch, citing a report from Tom's Hardware, Google engineers and open source project maintainers were being buried under invalid or hallucinated reports, that is, descriptions of vulnerabilities that simply don't exist in the analyzed code.

The warning that had been building since 2025

This collapse didn't come out of nowhere. Back in 2025, TechCrunch itself had reported that cybersecurity experts were warning about the risk of "AI slop" (AI-generated junk) to bug bounty programs. The logic is simple to understand: generative AI tools have made producing plausible-looking technical text cheaper, but they don't guarantee that the technical content is correct.

An AI agent can read a repository, generate a vulnerability hypothesis that looks like a professional report, cite real lines of code and even suggest a CVE, without there actually being an exploitable flaw there. For those who receive these reports, each one has to be manually triaged before being discarded, which takes the same time as a legitimate report, just without the same payoff.

Why this weighs more heavily on open source

Closed corporate bug bounty programs, such as those for proprietary products, usually have dedicated security teams and more mature triage processes. Google's OSS VRP, on the other hand, rewards findings in open source projects the company uses or maintains, many of them with lean maintenance that depends on just a handful of people.

This creates an important asymmetry:

  • Large companies can pause the program, redirect researchers to other initiatives and wait for the landscape to mature.
  • Independent maintainers of open source libraries and frameworks, who have no bounty of their own and no triage team, remain exposed to the same kind of automated submission, except without the option to "pause" anything, because they often receive these reports by email, a GitHub issue or a responsible disclosure form.

In practice, Google's episode works as an amplified warning sign for anyone who maintains an open project in Brazil or anywhere else: the flood of AI-generated reports isn't a problem exclusive to big tech, it's a structural problem for any vulnerability disclosure channel that accepts external submissions.

What changes in practice for open source maintainers

For teams that run, or are considering running, bug bounty programs on their own repositories, Google's case reinforces some decisions that had already been under discussion in the industry:

  1. Require a reproducible proof of concept: a report without step-by-step instructions that actually exploit the flaw gets discarded faster.
  2. Layered triage: a first automated analysis (including with AI) to filter out duplicates and obvious hallucination patterns, before it reaches a human.
  3. Entry fee or minimum reputation: some bug bounty platforms are already discussing charging a researcher reputation filter to reduce the volume of low-quality submissions.
  4. Clear communication of validity criteria: spelling out, in the security disclosure README, what counts as an acceptable report avoids part of the noise generated by people who are just testing whether an AI agent can "find" a flaw.

None of these measures solve the root problem, which is how easy it has become to generate plausible reports at scale. But they do reduce the triage cost, which was exactly the breaking point cited by Google.

What remains unresolved

Google has not publicly detailed what structural changes it plans to make before the update promised for the first quarter of 2027. Based on the sources available, there is no official number of how many reports were received, nor the exact proportion of invalid submissions, only the characterization of a "vast majority".

While the OSS VRP is on hold, the company is advising researchers to consider its other bug bounty programs, which remain active. For the security community and for open source maintainers, the episode leaves a question without a ready answer: if even Google, with all the triage capacity and infrastructure it has, had to freeze an entire program because of the volume of AI-generated reports, what's left for the maintainer of a small project who doesn't have that kind of muscle?

Translated from the Brazilian Portuguese original · Read the original