AI·News & analysis
Google pauses its open-source bug bounty after a flood of AI-generated reports
Google has stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Rewards Program, saying most of a surge of automated submissions weren't valid.

Tide
Ripple
Sci-fi
3/10
Reality
Shipping
The bots found so many bugs that most of them weren't real.How we rate
Google has paused product vulnerability submissions to its open-source bug bounty, the OSS VRP, as of October 1.
It blames a surge of AI-generated, automated submissions, most of them invalid. Supply chain reports and earlier submissions aren't affected, and other Google programs stay open. Google plans to rework the program and share an update in early 2027.
What to know
- Google has stopped accepting product vulnerability reports to its Open Source Software Vulnerability Rewards Program (OSS VRP) as of October 1.
- Google says the pause is due to a significant rise in automated submissions, the vast majority of which are not valid.
- Supply chain reports and reports filed before October 1 aren't affected, and researchers can still use Google's other programs.
- Google says it will rework the program and give an update in the first quarter of 2027.
AI tools are making it easier than ever to hunt for software bugs, and that has created a new problem: far too many reports that aren't real. Google has paused part of its open-source bug bounty because of it, the company said in a post from its Google VRP account.
What did Google pause?
As of October 1, 2026, Google is no longer accepting product vulnerability submissions to its Open Source Software Vulnerability Rewards Program, or OSS VRP.
"We are temporarily no longer accepting OSS VRP product vulnerability submissions," Google said, as quoted by BleepingComputer. "This does not impact OSS VRP supply chain reports, or any outstanding reports."
The reason, in Google's words: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
Google announced the change in posts on X and on the program's website, TechCrunch reports. The program's rules page now states that "as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP," according to Help Net Security.
Help Net Security also reports that the reward table on the program's page now lists no amounts for product vulnerabilities in any of its four project tiers.
What is the OSS VRP?
The OSS VRP is Google's bug bounty for the open-source software it releases. It pays security researchers who find and privately report security flaws, BleepingComputer explains.
- Launched: August 2022
- Rewards: from $100 to $31,337
- Projects covered: Google-maintained open source like Go (Golang), Angular, Bazel, Protocol Buffers and Fuchsia, plus critical third-party dependencies
- Also covered: repository settings like GitHub Actions, app configurations and access controls
Google said the program would focus on flaws with the biggest impact on the software supply chain, BleepingComputer reports.
What counted as a bug?
The paused part of the program covered a wide range of problems. Under the program's scope, "any design or implementation issue in Google OSS that causes a product vulnerability substantially affecting the confidentiality or integrity of user data in software builds using Google OSS" was eligible, Help Net Security reports.
Projects were sorted into four tiers, from OT0 (Flagship) to OT3 (Low-priority), and whether a report was accepted depended on the project's tier and the type of vulnerability, according to Help Net Security.
That breadth is part of the problem. A wide scope plus easy automation means a lot of reports to check, and every one has to be reviewed by a person before anyone can tell whether it's real.
Why it matters: bug bounties only work if the reports are worth reading. TechCrunch notes that cybersecurity experts warned last year that AI-generated "slop" posed a serious risk to bug bounty programs. Google's pause is one of the clearest signs yet that the warning came true.
Why did it get overwhelmed?
The big picture: finding software bugs used to be slow, skilled, manual work. AI tools have changed that.
Tom's Hardware explains that finding and reporting these flaws was usually painstaking, manual work that required real skill. Large language models and automated bug-hunting scripts have nearly eliminated that cost and effort, which led to a flood of low-effort reports.
In other words, the barrier that used to keep reports rare, and mostly real, has largely disappeared.
==Google engineers and open-source maintainers were reportedly swamped by thousands of reports that claimed to find bugs but were invalid, unexploitable or outright hallucinations, Tom's Hardware reports.==
The result was that reviewers spent too much time checking fake findings instead of fixing real, critical vulnerabilities.
In real life Imagine running a lost-and-found where suddenly thousands of people report wallets that never existed. You'd spend all day checking claims instead of returning the real ones. That's roughly what happened here.
What's still open?
The pause is narrower than it might sound. According to Google, as reported by BleepingComputer and Help Net Security:
- Supply chain reports to the OSS VRP are still accepted.
- Earlier reports: product vulnerabilities submitted before October 1 aren't affected.
- Patch Rewards Program: researchers can still submit security patches for Google's open source, with bounties of up to $15,000 for high-impact fixes.
- Cloud VRP: Google says it may still accept product vulnerability reports through the Cloud VRP "for some Google Cloud repos impacting Google Cloud products," Tom's Hardware reports.
- Other VRPs: Google encourages researchers to "find impact across our other VRP programs and submit there instead."
What happens next?
What's next: Google says it's reworking the program.
"We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027," Google said in an update on its Bug Hunters website, as quoted by BleepingComputer.
The catch: Google hasn't said what will change, or whether product vulnerability rewards will return in the same form.
For context, Google's bug bounties are big business. Since its first program in 2010, Google has paid more than $81.6 million to security researchers. In 2025 it paid a record $17.1 million to more than 700 researchers, up 40% from $12 million in 2024, BleepingComputer reports.
Is this happening elsewhere?
Yes, and it's becoming a pattern.
- curl: in January, the maintainer of the popular curl tool ended the project's HackerOne bug bounty after being overwhelmed by AI-generated reports, BleepingComputer reports.
- Intel: in mid-September, Intel removed all financial rewards for flaws in its software, firmware, hardware and services reported through its Intigriti bug bounty program, which had paid up to $100,000 per flaw, according to BleepingComputer and Tom's Hardware. It hasn't explained why, and Tom's Hardware notes experts suspect AI reports played a part.
- Linux: Tom's Hardware reports that Linux kernel maintainers said this month they were "completely overwhelmed," as AI-powered bug hunters pushed the kernel to a record 2,000 vulnerabilities per release.
- Microsoft: it warned in May that AI tools are increasing the pace of vulnerability discovery and "can raise operational demands," BleepingComputer reports. Last month, Microsoft patched a record-breaking 966 flaws, including two actively exploited zero-days.
- Older Linux drivers: in a similar case, Tom's Hardware says Linux ended support for some older network drivers because of an influx of false AI-generated bug reports.
Help Net Security adds that the decision follows months of complaints from open-source maintainers and bug bounty programs about low-quality, AI-assisted reports.
For more on Google, see our Google topic page.
What it means for you
- If you're a security researcher: OSS VRP product reports are paused, so send findings to Google's other programs or the Patch Rewards Program.
- If you use AI to hunt bugs: verify findings before submitting. Unchecked reports are what triggered this pause.
- Watch for early 2027: Google has committed to an update on the program in the first quarter of 2027, which should show how it plans to handle automated reports.
- If you rely on open source: the pause doesn't mean less security work. Google says the goal is to free reviewers to focus on real issues.
The bottom line
Google has paused product submissions to its open-source bug bounty after a flood of mostly invalid, AI-generated reports. Other ways to report bugs remain open, and Google promises an update in early 2027. It's one more sign that AI is making bug hunting faster, and noisier.
Key facts
- Program
- Open Source Software Vulnerability Rewards Program (OSS VRP)
- Paused
- Product vulnerability submissions, as of October 1, 2026
- Reason
- A surge of automated submissions, mostly invalid
- Still open
- Supply chain reports, Patch Rewards Program, other VRPs
- Next update
- First quarter of 2027
Got questions?
Quick answers, plain wordsWhat did Google pause?
Google stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) as of October 1, 2026.
Why did Google pause the program?
Google says it's due to a significant rise in automated submissions, the vast majority of which are not valid. Tom's Hardware reports that engineers and maintainers were overwhelmed by reports that were invalid or contained hallucinations.
What is the OSS VRP?
It's Google's bug bounty for the open-source software it releases, such as Go, Angular, Bazel and Protocol Buffers. It launched in August 2022 with rewards from $100 to $31,337, BleepingComputer reports.
Can I still report bugs to Google?
Yes. Supply chain reports to the OSS VRP are still accepted, and researchers can use Google's other bug bounty programs, the Patch Rewards Program, and the Cloud VRP for some Google Cloud repositories.
What about reports already submitted?
Google says product vulnerabilities submitted before October 1, 2026 aren't affected.
When will the program come back?
Google hasn't said. It says it will rework this part of the program and commits to giving an update in the first quarter of 2027.
What is the Patch Rewards Program?
It pays for security improvements to Google's open-source projects. BleepingComputer reports it offers bounties of up to $15,000 for high-impact fixes.
Is Google the only company doing this?
No. BleepingComputer reports the curl project ended its HackerOne bug bounty in January over AI-generated reports, and Intel removed financial rewards from its bug bounty program in mid-September without explaining why.
How much has Google paid in bug bounties?
Google has paid more than $81.6 million to security researchers since its first program in 2010, including a record $17.1 million in 2025, according to BleepingComputer.
SourcesGoogle VRP on X
Topics and tagsGoogle, Cybersecurity, google, security
Related stories

Cloudflare releases Clef, open-weight AI models that make yes-or-no decisions fast
Clef and Clef-flash answer bounded questions for AI agents in milliseconds instead of writing text. Cloudflare hosts them and also gives away the weights, a direct challenge to TypeSafe's Jev.

Judge dismisses Chegg and Penske antitrust suits over Google's AI Overviews
Chegg and Rolling Stone publisher Penske Media said Google forced them to feed AI Overviews for free. Judge Amit Mehta ruled their antitrust claims don't hold up.

Google's Guided Vision lets Gemini Live describe the world for blind and low-vision users
Point your Android phone's camera at something and Gemini describes it out loud, then tells you how to move the camera if it can't see well. Google built it with the blind and low-vision community.
More in brief
- A record 27 startups raised billion-dollar rounds in Q3 as AI soaks up 64% of venture moneyOct 5
- ChatGPT will start showing picture ads while you generate imagesOct 5
- Windows 11 26H2 feels faster, but an audio bug is crashing some appsOct 5
- California legalizes plug-in balcony solar, but compliant kits aren't here yetOct 2
- Space Force retires the last of its Cold War missile-warning satellitesOct 2
- Anthropic commits $100 million to train 10,000 engineers to deploy ClaudeOct 2