
Google pauses open source bug bounty program following surge in automated AI submissions
Google has temporarily suspended its Open Source Software Vulnerability Rewards Program until 2027. The pause responds to an influx of invalid reports and hallucinations generated by automated tools.
Published by Jin · 2 min read · 5 OCT 2026
Google has paused its Open Source Software Vulnerability Rewards Program until early next year. The decision follows a significant rise in automated vulnerability submissions that overwhelmed both company engineers and open source maintainers.
The scope of the pause
Effective as of October 1, the temporary suspension applies specifically to the open source software bug bounty initiative. Google has stated that an update regarding the future of the program will be provided in the first quarter of 2027.
Cybersecurity experts and industry observers have previously warned that the widespread accessibility of generative AI tools could flood security pipelines with low-quality reports. This prediction appears to have materialized for Google's program.
Impact on maintainers
According to technical reports, maintainers and internal engineers found themselves inundated with submissions that were either entirely invalid or contained significant AI-induced hallucinations. Reviewing these automated reports diverted valuable time and resources away from genuine security research.
- Automated submissions surged across the platform.
- The vast majority of the recent reports lacked validity.
- Review teams faced severe operational strain.
While this specific open source program remains on hold, participants are encouraged to direct their security research toward Google's other active bug bounty programs. The company hopes to use the downtime to evaluate better filtering mechanisms for handling automated content in the future.
Source — Original announcement ↗
Worth a read?
Comments · 0