Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has paused its Open Source Software Vulnerability Rewards Program effective October 1, citing a large increase in automated and AI-generated submissions that are largely invalid. The company said it will reassess and provide an update in the first quarter of 2027, and directed researchers to its other bug bounty programs in the meantime.

Why It Matters
The move underscores how automated AI-generated reports are straining vulnerability triage for large open-source repositories and may force firms to rethink how they run or fund bug bounty efforts. It also affects security researchers and open-source maintainers who relied on the program for coordinated vulnerability disclosure and rewards.
Key Facts
- Program paused: Open Source Software Vulnerability Rewards Program paused as of October 1, 2026
- Reason given: Significant rise in automated/AI submissions, with the vast majority judged not valid
- Next update: Google promised an update in the first quarter of 2027
- Alternate options: Participants were directed to consider Google's other bug bounty programs
- Reporting: TechCrunch and Tom's Hardware previously warned and reported maintainers were overwhelmed by invalid or hallucinated reports
Google announced it has paused its Open Source Software Vulnerability Rewards Program starting October 1, attributing the suspension to a surge in automated submissions that the company says are mostly invalid. The company posted the notice on the program website and on X, and said it will provide a follow-up update in the first quarter of 2027. While the pause is in effect, participants are being asked to explore Google's other bug bounty offerings.
According to reporting cited by Google, engineers and open-source maintainers were strained by an influx of reports that contained errors or AI hallucinations, creating extra triage work and low signal for actual vulnerabilities. Google explicitly described the cause as "a significant rise in automated submissions, the vast majority of which are not valid." The company did not publish details on the volume of submissions or how many valid vulnerabilities had been found through the program before the pause.
This development follows earlier warnings from cybersecurity experts — reported last year by TechCrunch — that AI-generated or low-quality automated submissions could overwhelm bug bounty programs. Tom's Hardware also covered accounts of maintainers and engineers being inundated with reports that required extra effort to filter and verify, increasing operational burden.
By pausing the open-source rewards program, Google is signaling a need to reassess how to manage large-scale, automated input in vulnerability reporting workflows. For now, researchers who previously used the open-source program can still participate in Google's other bounty initiatives while the company evaluates changes and plans its next steps.
Keep Reading

Live updates: Trump taps Clayton to lead AI force; Cornell victim’s attorney alleges more involved in gang rape

TechCrunch Mobility: Reining in robotaxis

An AI couldn’t beat humans at StarCraft, so it decided to cheat
