Google pauses its open source bug bounty after a flood of invalid AI reports

Google stopped taking product vulnerability reports through its Open Source Software Vulnerability Rewards Program on October 1, saying most of a surge in automated submissions were invalid. An update is promised in early 2027.
What it means for founders
- If you run a bounty or a public security inbox, expect the same flood. Budget triage time, require a working proof of concept, and consider an invite only program before an open one.
- AI security tools that verify their own findings before a human sees them have a clear selling point. Precision, not volume, is what maintainers will pay for.
- Researchers who earned income from Google's open source program lose a channel until at least 2027. Expect more of them on other platforms and in private programs.
- Watch Google's update early next year. Whatever filtering it adopts may become the template other large programs copy.
The story
Google has stopped paying for one category of bug reports because too many of them were wrong. As of October 1, its Open Source Software Vulnerability Rewards Program (OSS VRP) no longer accepts product vulnerability submissions, and the company says it will explain what comes next in the first quarter of 2027.
What changed
The OSS VRP rewards researchers who privately report flaws in open source code Google maintains, including Go, Angular, Bazel, Protocol Buffers and Fuchsia, along with repository settings and the third party dependencies those projects rely on. It launched in August 2022 with payouts from $100 to $31,337.
Google's explanation, posted on X and on its Bug Hunters site, was brief: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." Tom's Hardware reported that Google engineers and the maintainers who triage these reports were swamped by submissions that were invalid or contained hallucinated details.
The pause is narrower than it first sounds. Supply chain reports to the OSS VRP are still accepted, and anything filed before October 1 will be handled as normal. Researchers can still send security fixes to the Patch Rewards Program, which pays up to $15,000 for high impact patches, and can report flaws in some Google Cloud open source repositories through the Cloud VRP. Google says it is reworking the program to cope with automated submissions.
Part of a wider pattern
Google is not the first to pull back. In January, the maintainer of curl ended the project's bounty on HackerOne after a stream of AI generated reports, and in mid September Intel removed cash rewards from its bounty program without giving a reason. Security researchers have warned for more than a year that cheap, machine written reports would overwhelm the people who review them.
The twist is that AI is also finding real bugs. Microsoft warned in May that AI tools are speeding up vulnerability discovery across the industry and adding to the workload of defenders, and it shipped fixes for a record 966 flaws last month. The problem is not that models cannot find vulnerabilities. It is that filing a plausible report now costs almost nothing, while checking one still takes a skilled human.
For scale, Google says it has paid more than $81.6 million to researchers since its first reward program in 2010, including a record $17.1 million to over 700 people in 2025.
What we don't know yet
Google has not said how many reports it received, what share were invalid, or what the reworked program will demand. Proof of exploit, identity checks, reputation thresholds or submission limits are all possible, but none has been announced.
Sources
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
More in Policy & Safety
- Ousted New Jersey official cites 59 chatbot answers to dispute harassment findings

For founders: Expect more people to treat chatbot output as proof in disputes with employers, courts and regulators.
The Verge · 19h ago - Rural data centers could win a new federal tax break starting January 1

For founders: For data center developers, GPU cloud providers and energy startups building in rural areas, the program could meaningfully lower the cost of capital.
WIRED · 1d ago - Trump names Jay Clayton to lead a new Super Intelligence Force

For founders: Federal policy is leaning toward coordination and promotion, not new rules.
TechCrunch · 20h ago - Meta's Muse agent keeps hourly profiles of the people in your life

For founders: Consumer agents are now judged on what they remember about third parties, not just about the user.
WIRED · 2d ago - OpenAI safety report lead quits days after three researchers were fired

For founders: If your product runs on OpenAI's models, safety turmoil is now a roadmap risk.
TechCrunch · 1d ago