Technology News • • 5-8 minutes

Google Freezes Its Open Source Bug Bounty: Flood of AI-Generated Reports Forces a Pause

Diego Cortés
Diego Cortés
Full Stack Developer & SEO Specialist
Share:
Google Freezes Its Open Source Bug Bounty: Flood of AI-Generated Reports Forces a Pause
Image generated with AI

Since October 1, 2026, Google's open source bug bounty no longer accepts new product vulnerabilities. The company blames a flood of AI-generated reports that, in its own words, are mostly invalid. Here is what changes, what still pays and why triage broke.

What Happened on October 1, 2026

Google Stops Accepting Product Vulnerabilities in the OSS VRP

The notice went up on the program's official account and on the Bug Hunters site: as of October 1, 2026, the Open Source Software Vulnerability Reward Program (OSS VRP) stopped taking product vulnerability reports. It is not a shutdown of the program or the end of its payouts, but a pause on one of its lanes: bugs in products across Google's ecosystem.

A "Significant Rise" in Automated Submissions: the Reason Google Gave

The company's wording is specific, so it is worth not stretching it: a "significant rise" in automated submissions and, of those, "the vast majority" invalid. Google published no percentages and no count of discarded reports, so any exact figure you see going around is a third-party estimate, not official data.

What Still Works

The pause is partial, and the map is worth keeping straight:

  • Supply chain reports to the OSS VRP are still accepted.
  • Reports submitted before October 1 are not affected.
  • Google's other reward programs (Chrome, Android, Cloud) keep their own lanes; Chrome's, for instance, still pays for flaws like the ones fixed in the latest Chrome security update.
  • The Patch Rewards Program remains open for security improvements in open source projects.

The Promise of an Update in the First Quarter of 2027

There is no reopening date. Google says it will work on redesigning this part of the program and will give an update in the first quarter of 2027. That is a commitment to report back, not a promise to reopen.

What the Bug Bounty Is, and Why It Isn't "the One for All Open Source"

A Google Program for Software in the Google Ecosystem, Launched in 2023

The OSS VRP was announced in August 2023 and focuses on vulnerabilities in open source software tied to Google's ecosystem. It is not the bug bounty for all open source on the planet: a project outside that orbit has its own program, or none.

What It Paid For: Real Impact and Supply Chain

The program rewarded two distinct things: flaws with real product impact and supply chain compromises, meaning cases where someone tampers with the process that builds or ships a dependency. That second lane is still alive.

Why AI Breaks a Reward Program

The Party Paying for Results Doesn't Pay for Triage

A bug bounty pays for an outcome: a confirmed vulnerability. It does not pay for the work of checking whether that outcome is real — the receiver absorbs that cost. There is the crack: writing a report that reads like a report costs almost nothing today, while reading it, trying to reproduce it and deciding whether it deserves a payout still costs human time.

Hallucination, Weak Code and Real Vulnerability

All three show up looking the same. A model hallucination describes a flaw that does not exist; a code-quality note flags something improvable with no security impact; a real vulnerability is the real thing. The reviewer cannot tell until they try to reproduce it, so the effort is spent before anyone knows whether there was anything there.

Why Volume Doesn't Add Up: How Noise Buries Good Findings

Thousands of reports do not make a team better at reading them: they make a queue. The underlying risk is not receiving fewer findings, but losing the good ones among the bad. If you must review a hundred reports to find one that holds, attention — the scarce resource — runs out before you reach it.

Why Filtering With AI Doesn't Close the Loop

An automated filter can discard a rare but genuine report. That balance between noise and false negatives is exactly what Google had been tuning with rules, and in the end what pushed it to pause the product lane.

What Google Had Already Tried Before Pausing

Tighter Rules in Early 2026: a Reproducer or a Merged Patch

Before giving up, Google tightened the program's rules in early 2026: for certain reward tiers it began requiring higher-quality proof, such as an OSS-Fuzz reproduction or a merged patch in the project. The goal was to filter out weak reports and focus on real impact.

Filtering Without Losing Real Findings: the Dilemma

Even with those rules, the volume stayed too high for a finite team. It is the dilemma of every reward program: tightening the filter cuts noise, but also risks shutting out something legitimate. Google chose to stop the product lane and rethink it.

Not an Isolated Case: the 2026 Pattern

curl Shut Down Its Bug Bounty and Its Maintainer Told the Story in Public

The curl project closed its reward program on January 31, 2026, after years in operation, and its maintainer, Daniel Stenberg, publicly explained why it had become unsustainable. That is external context, not part of Google's case, but it traces the same pattern.

HackerOne Paused the Internet Bug Bounty

On March 27, 2026, HackerOne suspended new submissions to its Internet Bug Bounty, citing a rise in AI-assisted findings; payout adjustments followed later. And volunteer-run projects, with no budget for triage, froze their own programs.

The Common Pattern: Cheap Discovery, Expensive Verification

In every case the same part breaks: finding candidates got cheaper, tending to them did not. When that asymmetry grows, a program stops paying for what it receives and starts paying to clean it up. Underneath sits the same tension you see when zero-days under mass exploitation get patched: verification work does not automate itself.

What This Pause Costs and What It Buys

The Incentive That Disappears

What the ecosystem loses is the financial incentive to audit that specific software: with no reward, fewer eyes are looking. What Google gains is time: no more burning human hours on noise. And the real risk is not fewer reports, but losing the good ones among the bad.

What You Can Do: Maintainers, Researchers and Funders

If You Maintain a Project

Write your policy before you need it: require a reproducible proof of concept, the affected version or commit and a demonstrable impact; ask for a patch when possible and state in writing what you do with AI-assisted reports. A form with mandatory fields heads off the bare "I think there might be a problem here".

If You Research Security With AI Help

Using an assistant is not the problem; submitting without verifying is. A report that survives triage carries a minimal reproducer, evidence, the patch if you have one and follow-up. Sending it unchecked burns your reputation and that of the assistant you used.

If You Fund a Program

Measure the share of valid reports, not the number of reports. Volume is easy to inflate; the proportion of real findings tells you whether a program is healthy or drowning.

What to Watch in 2027

Three things, with no firm date: which validation model Google picks to reopen this lane, whether the pattern spreads to other vendors, and whether shared standards for AI-assisted reports emerge. For now, the only confirmed item is the update promised for the first quarter of 2027.

Conclusion

The pause on Google's open source bug bounty is not the end of reward programs, nor a verdict against AI: it is a program that received more work than it could verify. If you maintain code or research security, the practical lesson is simple: what gets submitted unchecked has a cost, and someone else pays it. Keep reading the blog to follow how security triage evolves in 2027.

Categories