targeting.ai Society Signal

Case 55 · Open source and security

Google freezes open source bug bounty program after flood of AI-generated junk reports

Reported 5 Oct 2026 · entered the ledger 5 Oct 2026 · last checked 5 Oct 2026 · Side effect

Google halted product flaw submissions to its open-source Vulnerability Reward Program (OSS VRP) until 2027 after maintainers were inundated with thousands of AI-generated, hallucinated vulnerability reports that consumed triage time without uncovering actual flaws.

The institution Google Open Source Bug Bounty Program institution · US
The mechanism Friction removed externality scale 3 of 5, fast
Adaptation reform the rule itself was rewritten
The case as the ledger holds it
The assumption that broke
Vulnerability reporting required human effort to identify and articulate valid security flaws, keeping submission volumes manageable and signal-to-noise high.
The first-order effect
Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted review time without finding real bugs, forcing a complete freeze of product flaw submissions until 2027.
Who pays
Program maintainers and security triagers whose time was consumed vetting fabricated reports, as well as genuine security researchers locked out of submitting product vulnerabilities. · group: Volunteers and reviewers
Scale and speed
3 of 5 · fast
Evidence 5 pages read
  • X (@MuhammadZAKhan) ↗ 5 Oct 2026 · social source, review
    Google just froze its open source bug bounty program because AI generated reports flooded it with junk. The model did not speed up security work. It created a slop filtering job nobody wanted.
  • x ↗ 5 Oct 2026 · social source, review
    Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports. → The pause took effect October 1 for product vulnerabilities in the OSS VRP → Supply-chain reports and some Google Cloud repos are still accepted → Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited
  • x ↗ 4 Oct 2026 · social source, review
    Google just became the biggest name to admit what the AI slop era is costing: it froze its own open-source bug bounty. As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027. Its reason, in its own words: 'a significant rise in automated submissions, the vast majority of which are not valid.'
  • X (@GenAISpotlight) ↗ 3 Oct 2026 · social source, review
    Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs. The freeze lasts until 2027 while Google redesigns how it accepts security disclosures.
  • TechBuzz ↗
    Google just hit the pause button on its open source bug bounty program, and the reason reveals a troubling new reality in cybersecurity. The tech giant froze the initiative after experiencing what it calls a 'significant rise' in AI-generated submissions that are overwhelming its security review process.
The second reader every claim, checked against the page
ClaimVerdictNote
Google has temporarily frozen its open source bug bounty program after experiencing what the company describes as a 'significant rise' in AI-generated submissions. supported Page 1: "Google has temporarily frozen its open source bug bounty program after experiencing what the company describes as a 'significant rise' in AI-generated submissions."
The decision marks one of the first high-profile cases where AI spam has forced a major company to shut down a critical security program. supported Page 1: "The decision marks one of the first high-profile cases where AI spam has forced a major company to shut down a critical security program."
Bug bounty submissions described by researchers contain 'hallucinated function names and non-existent code paths.' supported Page 1: "described receiving reports that contain hallucinated function names and non-existent code paths."
Google has not announced when it plans to reopen the program or what specific changes it will implement. supported Page 1: "Google hasn't announced when it plans to reopen the program or what changes it might implement to address the AI submission problem."
Google halted product flaw submissions to its open-source bug bounty program after getting flooded with fake AI-generated reports. supported Page 2: "Google halted product flaw submissions to its open-source bug bounty program after getting flooded with fake AI-generated reports."
Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs. supported Page 2: "Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs."
The freeze lasts until 2027 while Google redesigns how it accepts security disclosures. supported Page 2: "The freeze lasts until 2027 while Google redesigns how it accepts security disclosures."
The supply-chain lane is still live. supported Page 2 comment by @peritumAI: "The supply-chain lane is still live."
Google just froze its open source bug bounty program because AI generated reports flooded it with junk. supported Page 3: "Google just froze its open source bug bounty program because AI generated reports flooded it with junk."
The model did not speed up security work. It created a slop filtering job nobody wanted. supported Page 3: "The model did not speed up security work. It created a slop filtering job nobody wanted."
Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports. supported Page 4: "Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports."
The pause took effect October 1 for product vulnerabilities in the OSS VRP supported Page 4: "The pause took effect October 1 for product vulnerabilities in the OSS VRP"
Supply-chain reports and some Google Cloud repos are still accepted supported Page 4: "Supply-chain reports and some Google Cloud repos are still accepted"
Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited supported Page 4: "Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited"
Intel has also suspended its bounty program, which paid up to $100,000 per flaw supported Page 4: "Intel has also suspended its bounty program, which paid up to $100,000 per flaw"
As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027. supported Page 5: "As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027."
Google stated its reason as 'a significant rise in automated submissions, the vast majority of which are not valid.' supported Page 5: "Its reason, in its own words: 'a significant rise in automated submissions, the vast majority of which are not valid.'"
Linux kernel maintainers got flooded by AI-generated CVE filings, with some releases hitting ~2,000. supported Page 5: "Linux kernel maintainers got flooded by AI-generated CVE filings — some releases hit ~2,000."
curl killed its bounty in January. supported Page 5: "curl killed its bounty in January."
HackerOne paused new Internet Bug Bounty submissions in March. supported Page 5: "HackerOne paused new Internet Bug Bounty submissions in March."
Intel quietly suspended its paid bounty — offering up to $100,000 a flaw — without giving a reason. supported Page 5: "Last month Intel quietly suspended its paid bounty — up to $100,000 a flaw — without giving a reason."
Google's own AI agent found 20 real vulnerabilities in open source last year. supported Page 5: "Google's own AI agent found 20 real vulnerabilities in open source last year."