Google Pauses Its Open Source Bug Bounty: Too Many AI Reports, Mostly Wrong
The first big bug bounty to fold under AI slop is Google's. Google has paused its Open Source Software Vulnerability Rewards Program until next year, effective October 1, and promised "an update" in the first quarter of 2027. TechCrunch reported it on Sunday.
Google's own explanation is one sentence: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." Per Tom's Hardware, Google engineers and the open source maintainers who triage these reports were buried in reports that were invalid or contained hallucinations. Researchers are being pointed to Google's other bounty programs in the meantime.
This is the flip side of every "agent found a zero-day" headline this year. Finding a real bug got cheaper, and generating something shaped like a bug report got almost free. A bounty is a market that pays for verified findings, and verification is still done by a human maintainer reading the report. When submission cost drops to zero and verification cost stays the same, the market jams. Pausing is the only lever Google had that worked right away.
What comes back in 2027 will be worth watching. The likely shapes are proof-of-exploit requirements, reputation gating, or charging a deposit per submission. All three move the cost of verification back onto the submitter. That's the same pattern open source projects keep landing on for AI pull requests: the person submitting has to prove the work, not the person reviewing.
Link: techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/ and bughunters.google.com/open-source-security
← Back to all articles
Google's own explanation is one sentence: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." Per Tom's Hardware, Google engineers and the open source maintainers who triage these reports were buried in reports that were invalid or contained hallucinations. Researchers are being pointed to Google's other bounty programs in the meantime.
This is the flip side of every "agent found a zero-day" headline this year. Finding a real bug got cheaper, and generating something shaped like a bug report got almost free. A bounty is a market that pays for verified findings, and verification is still done by a human maintainer reading the report. When submission cost drops to zero and verification cost stays the same, the market jams. Pausing is the only lever Google had that worked right away.
What comes back in 2027 will be worth watching. The likely shapes are proof-of-exploit requirements, reputation gating, or charging a deposit per submission. All three move the cost of verification back onto the submitter. That's the same pattern open source projects keep landing on for AI pull requests: the person submitting has to prove the work, not the person reviewing.
Link: techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/ and bughunters.google.com/open-source-security
Comments