Google Halts Open-Source Bug Bounties as AI Junk Floods the Queue
Google Halts Open-Source Bug Bounties as AI Junk Floods the Queue
Google has frozen its Open Source Software Vulnerability Rewards Program, turning a bug bounty designed to uncover weaknesses in its open-source code into the latest casualty of the AI-generated-report boom.
The program rewarded researchers for identifying vulnerabilities across Google’s open-source ecosystem. But on October 1, the company paused it after what it described as a sharp influx of automated filings. Google said the suspension stemmed from a “significant rise in automated submissions, the vast majority of which are not valid.”
The practical problem was not simply volume. Google engineers and open-source maintainers were reportedly swamped by reports that were either invalid or contained hallucinated technical claims — work that must still be read, checked and dismissed before legitimate findings can receive attention.
For Google, the freeze is a defensive measure: participants are being directed toward its other bug bounty programs while the company reassesses the open-source scheme. It has promised an update in the first quarter of 2027, meaning the pause will last at least into next year.
For the wider open-source community, however, the episode reinforces an older warning that AI can degrade security reporting as easily as it can accelerate it. Similar waves of poor-quality submissions have troubled Linux maintainers, according to reports, placing volunteer-led projects under pressure from claims that look plausible at first glance but do not hold up.
The tension is stark: bug bounties depend on broad participation, yet their value rests on scarce human judgment. Google’s decision suggests that, for now, the cost of sorting AI slop has overtaken the benefit of keeping this particular pipeline open.
Write a comment