Google has temporarily suspended its open source bug bounty program, citing a "significant rise" in submissions generated by artificial intelligence. The program, known as Google’s Open Source Software Vulnerability Rewards Program, was paused as of October 1, according to the company.
The tech giant stated that the halt is "due to a significant rise in automated submissions, the vast majority of which are not valid." Google has indicated it plans to provide an update on the program's status in the first quarter of 2027.
The Open Source Software Vulnerability Rewards Program was established to compensate researchers for identifying vulnerabilities within Google's open source software. However, the influx of AI-generated reports has reportedly overwhelmed the system.
Context and Background
The challenges faced by Google's program align with prior warnings from cybersecurity experts. Last year, TechCrunch reported that these experts had cautioned that "AI slop" posed a serious risk to the efficacy of bug bounty programs.
According to a report by Tom’s Hardware, Google engineers and open source maintainers were reportedly overwhelmed by the volume of submissions. These reports were described as either invalid or containing "hallucinations," a term often used to describe fabricated or incorrect information generated by AI systems.
Google communicated the pause through posts on X and its program website.
Future Steps
While the open source bug bounty program remains suspended, Google has encouraged participants to consider submitting findings to its other existing bug bounty programs. The company has committed to offering further information regarding the paused program early next year.






