Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google has paused its Open Source Software Vulnerability Rewards Program, blaming a "significant rise" in AI submissions, according to posts on X and the program website. The program, which rewarded researchers for finding vulnerabilities in the company's open source software, was paused as of October 1.
Google said it will provide "an update" in the first quarter of 2027. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said.
According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. Participants are encouraged to consider Google's other bug bounty programs in the meantime.
TechCrunch reported last year that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
AI slop seems to be overwhelming bug bounty programs.