Google has paused its Open Source Software Vulnerability Rewards Program, the bug bounty scheme that paid researchers for finding vulnerabilities in its open source software. The program was frozen as of October 1, according to posts on X and on the program's website, with the company promising an update in the first quarter of 2027.
The reason given is a "significant rise in automated submissions, the vast majority of which are not valid," TechCrunch reported. In other words, AI-generated bug reports — often hallucinated or simply wrong — have overwhelmed the engineers and open source maintainers who have to read them. Google is pointing participants toward its other bug bounty programs in the meantime.
Why AI slop broke Google's bug bounty
This did not come out of nowhere. TechCrunch reported last year that cybersecurity experts were already warning that AI slop posed a serious risk to bug bounty programs, and Google's open source scheme now looks like the clearest case of that prediction coming true.
Bug bounty programs depend on a simple bargain: researchers spend time hunting real flaws, and companies pay for the ones that matter. When automated tools can generate plausible-looking reports at almost no cost, the volume explodes while the quality collapses. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
For Google, the trade-off stopped making sense. Reviewing a flood of fake or inaccurate vulnerability reports costs engineering time and can bury the genuine security findings underneath.
Google bug bounty: what changes now
The pause applies specifically to the Open Source Software Vulnerability Rewards Program, not to Google's other bug bounty efforts. The company said it will provide an update in the first quarter of 2027, leaving the scheme dormant for well over a year.


