
- Google suspended its Open Source Software Vulnerability Rewards Program as of October 1, 2026.
- The stated reason: a significant rise in automated submissions, the vast majority of which are not valid.
- Google expects the program to resume in the first quarter of 2027.
- Researchers are being pointed to Google’s other bug bounty programs in the meantime.
What happens to a security program when the cheapest thing to produce is a convincing but wrong vulnerability report? Google just gave a concrete answer: it paused the program. The company froze its open source bug bounty after a surge of AI-generated submissions that overwhelmed the people who have to read them.
What Google Actually Announced
A pause, not a shutdown
According to TechCrunch, Google suspended its Open Source Software Vulnerability Rewards Program effective October 1, 2026. Google cited a “significant rise” in automated submissions, “the vast majority of which are not valid.” The company announced the move through posts on X and its official bug hunters website, and said it expects to bring the program back in the first quarter of 2027.
Participants are encouraged to send vulnerabilities through Google’s other existing bug bounty programs while the open source program is on hold.
Trend Insight — A bounty pays per accepted report, which makes it a natural target for anyone who can generate reports at near-zero cost. When submission volume stops reflecting real findings, the review queue becomes the bottleneck, and pausing is the blunt but fast fix.
Why AI Slop Hits Bounties Hardest
Reviewers carry the cost
Reporting described by TechCrunch says Google engineers and open source maintainers were buried in invalid reports, many containing AI hallucinations such as flaws in code paths that do not exist. Generating such a report takes seconds. Disproving it takes a human triager real time, and open source maintainers are often volunteers.
This is not a new worry. TechCrunch had already flagged in July 2025 that AI-generated content posed risks to bug bounty programs. The October 2026 freeze shows the concern has moved from warning to operational reality at one of the largest programs in the industry.
Trend Insight — The same dynamic applies to any intake channel that rewards volume: support tickets, pull requests, and job applications. Expect more programs to add proof-of-concept requirements or reputation gates.
What Teams Should Do Now
Treat AI findings as leads, not verdicts
If your team uses AI tools to scan code, require a working reproduction before anything is filed upstream. Maintainers are the scarce resource, and a verified report is worth far more than ten plausible ones. If you run your own bounty or intake form, consider rate limits and a lightweight verification step so real researchers are not drowned out.
For companies that depend on open source, the pause is also a reminder that upstream vulnerability discovery has less incentive funding for now. Budget internal review time for your most critical dependencies until the program returns.
Trend Insight — The next phase of AI security tooling is less about finding more candidate bugs and more about proving which ones are real. Verification, not generation, is where the value moves.
Related
- Apple Just Locked a Door AI Agents Were Walking Through
- OpenAI Just Came for Microsoft’s Office
- AMD Just Paid $8.2 Billion for a Chip-Less Startup
- Google Gemini and the Flipkart buy button
Sources
- TechCrunch – Google froze its open source bug bounty program due to a significant rise in AI submissions
- TechCrunch AI category
- GeekNews
AI Biz Insider · AI Trends EN · aibizinsider.com

댓글 남기기