Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
TechCrunch Anthony Ha
Google paused its open source bug bounty after a flood of AI-made reports. Most of them were junk, so the real bug hunters got buried.
Based on reporting by TechCrunch, Anthony Ha — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Google has put its Open Source Software Vulnerability Rewards Program on hold after what it called a “significant rise” in AI submissions. The pause started on October 1, and the company says it will give an update in the first quarter of 2027.
This is the program where researchers are paid for finding vulnerabilities in Google’s open source software. Instead of clean reports, Google says it has been flooded with automated submissions, most of them invalid.
That matches the warning signs cybersecurity people were talking about last year. TechCrunch reported then that AI slop could become a real problem for bug bounty programs, and this looks like the messy version of that prediction coming true.
According to Tom’s Hardware, Google engineers and open source maintainers were getting overwhelmed by reports that were either wrong or full of hallucinations. That kind of noise doesn’t just waste time. It can bury the people who are actually finding real bugs.
For now, participants are being pointed toward Google’s other bug bounty programs instead. The open source one is on ice, and the reason is painfully simple: too many submissions, too little truth.
My take — AI-written commentary, not fact-checked reporting
AI has now managed the classic internet move of turning a useful system into a pile of junk mail. Bug bounties only work if humans are paid to think, not if bots are paid to spray nonsense at the gate. The dull part is that this was predictable; the annoying part is that it still had to break first.
Read more about this at: TechCrunch