in ,

Google Pauses Open Source Bug Bounty Program After AI Reports Surge

Google Pauses Open Source Bug Bounty Program After AI Reports Surge

Google has paused its open source bug bounty program until next year. The company blames a “significant rise” in AI submissions for this decision.

Cybersecurity experts had already warned about this risk last year. They cautioned that AI-generated junk, often called “AI slop,” posed a serious threat to bug bounty programs. That warning appears to have become reality. The issue is now hitting Google’s Open Source Software Vulnerability Rewards Program directly. This program rewards researchers for finding vulnerabilities in the company’s open source software.

Hosting 75% off

In posts on X and on the program’s official website, Google confirmed the pause. The bug bounty program paused as of October 1. The company promised to provide “an update” sometime in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open-source maintainers were getting overwhelmed. Many reports flooding in were invalid. Others contained outright hallucinations generated by AI tools.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

This situation reflects a broader challenge spreading across the security research community. Bug bounty programs were originally designed around a simple idea. Skilled researchers manually test software, find real flaws, and submit detailed reports in exchange for payment. That system worked reasonably well for years.

Read More: Can AI’s Image Problem Be Fixed With Super Intelligence and Safety?Can AI’s Image Problem Be Fixed With Super Intelligence and Safety?

The rise of generative AI tools has changed the equation considerably, though. Anyone can now run automated scanners or prompt an AI model to “find vulnerabilities” in a codebase. The result is often a flood of low-quality, speculative, or entirely fabricated reports.

These submissions still require human review, even when they turn out to be worthless. That review process consumes real engineering time at companies already stretched thin on security staffing.

Other major tech companies have reportedly faced similar pressures recently, though most haven’t gone as far as pausing a program entirely. Some have started requiring additional verification steps or proof-of-concept exploits before accepting submissions.

Others have adjusted reward structures to discourage low-effort or automated reports. Google’s pause suggests the problem has grown severe enough that a temporary shutdown felt more practical than incremental fixes.

In the meantime, Google is encouraging participants to consider its other bug bounty programs instead.

Hosting 75% off

Written by Hajra Naz

Can AI’s Image Problem Be Fixed With Super Intelligence

Can AI’s Image Problem Be Fixed With Super Intelligence and Safety?

OpenAI Safety Employee Resigns, Says Company Culture Is Broken

OpenAI Safety Employee Resigns, Says Company Culture Is Broken