Google Pauses Open Source Bug Bounty Over AI Report Flood

Google Pauses Open Source Bug Bounty Over AI Report Flood

Google has put one of its security reward programs on hold. The company says too many of the reports it now receives are machine-generated, and most of them are wrong.

The program in question is Google's Open Source Software Vulnerability Rewards Program. Under it, outside researchers could earn money for finding security flaws in the open source software Google maintains. As of October 1, new submissions are paused. Google says it will share "an update" in the first quarter of 2027, so the program is effectively offline until next year.

What Google said

Google announced the pause in posts on X and on the program's own website. The explanation was short:

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said.

Google did not say how many reports it received or what share were invalid. It also did not say that every automated report came from an AI system. The direction is still clear. The volume of submissions rose, the quality fell, and the people reviewing them could not keep up.

Tom's Hardware reported that Google engineers and open source maintainers were overwhelmed by reports that were either invalid or contained hallucinations. In AI terms, a hallucination is content a model presents as fact but that is made up. In a vulnerability report, that could mean a function that does not exist, a code path that never runs, or an exploit that cannot work.

For now, Google is pointing researchers to its other bug bounty programs. Those remain open.

How bug bounties work, and why volume matters

A bug bounty program pays outside people to find security problems before attackers do. The model depends on a simple exchange. Researchers spend time hunting for flaws. The company spends time checking what they find. Valid findings get paid and fixed.

That exchange only works if the checking side can cope. Every report has to be read, reproduced and assessed by someone with enough knowledge of the code. A good report saves the vendor time. A bad report costs time, and a convincing bad report costs the most, because it takes longer to rule out.

Open source adds another layer. Many reports land on the desks of maintainers, the developers responsible for keeping a project running. Their time is limited, and an invalid report that looks plausible pulls them away from real fixes.

A warning that came true

This problem did not arrive without notice. Last year, TechCrunch reported that cybersecurity experts were warning that "AI slop" - low-quality content produced in bulk with AI tools - posed a serious risk to bug bounty programs. The concern was that cheap generation would let people send large numbers of reports in the hope that a few would pay out, while reviewers absorbed the cost.

Google's pause is a concrete example of that warning playing out at a large company. It is also notable that Google chose to stop the program rather than simply filter harder. That suggests filtering at the current volume was not workable, at least not quickly.

The odd position of AI in security

There is a tension here. AI tools are getting better at real security work, and some models now show strong results at building working exploits. Google itself is investing in defensive cyber AI. The capability is not the issue in this case. The issue is what happens when people point these tools at a reward system without checking the output.

A model can write a report that reads like expert work in seconds. Confirming whether the claim is true still takes a human with context. When the cost of producing a report drops toward zero but the cost of reviewing one does not, the reviewer loses.

The Bigger Picture

This looks like part of a wider pattern: open systems that relied on good faith are closing or narrowing as automated traffic grows. Reddit's decision to end RSS feeds and its public API over AI scrapers is a different case, but the logic is similar. When AI makes abuse cheap, the open door gets harder to keep open.

For researchers, the takeaway is practical. Unverified AI output does not just fail to earn a reward. It can shut a program down for everyone, including people doing careful work.

It is worth watching what Google announces in early 2027. Possible responses include stricter submission rules, requirements to show a working proof of concept, or limits on who can take part. Whether other vendors follow with similar pauses will show if this is a Google problem or a structural one for bug bounties as a whole. The open question is whether reward programs can adapt their review process fast enough, or whether some will stay closed.