Why Google paused its open source bug bounty program

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1 after a sharp increase in automated reports. The company says most of those submissions are not valid, and it plans to provide an update in the first quarter of 2027.

Why Google paused its open source bug bounty program

Google has put its Open Source Software Vulnerability Rewards Program on hold after a surge of automated vulnerability reports created too much noise for the people reviewing them.

The pause began on October 1. Google said it will provide “an update” in the first quarter of 2027, while pointing participants toward its other bug bounty programs in the meantime.

What Google paused

The affected program is Google’s Open Source Software Vulnerability Rewards Program. It rewarded researchers for finding vulnerabilities in Google’s open source software.

Bug bounty programs depend on a basic exchange: researchers send in useful security findings, and maintainers or security teams review those findings to decide whether they are valid. When that pipeline works, it can help software teams discover issues they might otherwise miss.

In this case, the problem was not that Google stopped caring about open source security. The issue was the volume and quality of submissions reaching the program.

The AI submission problem

Google blamed the pause on a “significant rise” in AI submissions. The company said the reports were largely automated, and that most of them did not hold up under review.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. That matters because every report still demands attention. Even a weak or wrong submission can require someone to read it, check the claim, compare it against the code, and decide whether there is a real vulnerability.

AI-generated reports can create a difficult review burden when they look plausible but fail on the facts. A report may describe a flaw that is not actually present, misunderstand how a project works, or present invented details as if they were evidence. The source describes this as a problem of invalid reports and hallucinations, not as a confirmed wave of real vulnerabilities.

Why invalid reports are costly

For an open source bug bounty program, a flood of low-quality submissions can change the work from security triage into report triage. Instead of spending time on valid vulnerabilities, maintainers may have to spend time sorting through claims that should never have been submitted.

That creates several practical problems:

  • Reviewer time gets consumed. Engineers and maintainers have to inspect submissions before they can reject them.

  • Useful findings can become harder to spot. Valid reports may sit in the same queue as automated noise.

  • The program’s signal can weaken. A bounty program depends on reports that are specific, accurate, and actionable.

The source points to a wider concern that cybersecurity experts had already raised: AI slop can pose a serious risk to bug bounty programs. Google’s pause shows how that risk can become operational. The challenge is not just whether AI can generate security language, but whether the output is reliable enough for human reviewers to spend time on it.

What happens next

Google has not said that the Open Source Software Vulnerability Rewards Program is permanently closed. It has paused the program and said an update will come in the first quarter of 2027.

Until then, participants are encouraged to consider Google’s other bug bounty programs. That means the company is still directing security researchers toward other reporting channels, even as this specific open source program is frozen.

The pause also sends a clear message about automated vulnerability submissions. Speed alone is not useful if the result is a large pile of invalid claims. For bug bounty researchers, the value of a report still depends on whether it identifies a real issue in a way maintainers can verify.

For open source maintainers, the episode highlights a growing review problem. AI tools may lower the effort needed to produce a report, but they do not remove the need for accuracy. When automated reports arrive at scale and most are not valid, the cost shifts to the people maintaining the software.

Google’s next update will determine how the program moves forward. For now, its open source bug bounty program is paused because the review system was hit by too many automated submissions that did not meet the standard needed for useful security work.