Case 55 · Open source and security
Google freezes open source bug bounty program after flood of AI-generated junk reports
Reported 5 Oct 2026 · entered the ledger 5 Oct 2026 · last checked 5 Oct 2026 · Side effect
Google halted product flaw submissions to its open-source Vulnerability Reward Program (OSS VRP) until 2027 after maintainers were inundated with thousands of AI-generated, hallucinated vulnerability reports that consumed triage time without uncovering actual flaws.
The institution
Google Open Source Bug Bounty Program
institution · US
The mechanism
Friction removed
externality scale 3 of 5, fast
Adaptation
reform
the rule itself was rewritten
The case
- The assumption that broke
- Vulnerability reporting required human effort to identify and articulate valid security flaws, keeping submission volumes manageable and signal-to-noise high.
- The first-order effect
- Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted review time without finding real bugs, forcing a complete freeze of product flaw submissions until 2027.
- Who pays
- Program maintainers and security triagers whose time was consumed vetting fabricated reports, as well as genuine security researchers locked out of submitting product vulnerabilities. · group: Volunteers and reviewers
- Scale and speed
- 3 of 5 · fast
Evidence
-
X (@MuhammadZAKhan) ↗
5 Oct 2026
· social source, review
Google just froze its open source bug bounty program because AI generated reports flooded it with junk. The model did not speed up security work. It created a slop filtering job nobody wanted.
-
x ↗
5 Oct 2026
· social source, review
Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports. → The pause took effect October 1 for product vulnerabilities in the OSS VRP → Supply-chain reports and some Google Cloud repos are still accepted → Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited
-
x ↗
4 Oct 2026
· social source, review
Google just became the biggest name to admit what the AI slop era is costing: it froze its own open-source bug bounty. As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027. Its reason, in its own words: 'a significant rise in automated submissions, the vast majority of which are not valid.'
-
X (@GenAISpotlight) ↗
3 Oct 2026
· social source, review
Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs. The freeze lasts until 2027 while Google redesigns how it accepts security disclosures.
-
TechBuzz ↗
Google just hit the pause button on its open source bug bounty program, and the reason reveals a troubling new reality in cybersecurity. The tech giant froze the initiative after experiencing what it calls a 'significant rise' in AI-generated submissions that are overwhelming its security review process.
The second reader
| Claim | Verdict | Note |
|---|---|---|
| Google has temporarily frozen its open source bug bounty program after experiencing what the company describes as a 'significant rise' in AI-generated submissions. | supported | Page 1: "Google has temporarily frozen its open source bug bounty program after experiencing what the company describes as a 'significant rise' in AI-generated submissions." |
| The decision marks one of the first high-profile cases where AI spam has forced a major company to shut down a critical security program. | supported | Page 1: "The decision marks one of the first high-profile cases where AI spam has forced a major company to shut down a critical security program." |
| Bug bounty submissions described by researchers contain 'hallucinated function names and non-existent code paths.' | supported | Page 1: "described receiving reports that contain hallucinated function names and non-existent code paths." |
| Google has not announced when it plans to reopen the program or what specific changes it will implement. | supported | Page 1: "Google hasn't announced when it plans to reopen the program or what changes it might implement to address the AI submission problem." |
| Google halted product flaw submissions to its open-source bug bounty program after getting flooded with fake AI-generated reports. | supported | Page 2: "Google halted product flaw submissions to its open-source bug bounty program after getting flooded with fake AI-generated reports." |
| Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs. | supported | Page 2: "Maintainers were overwhelmed by thousands of hallucinated flaw reports that wasted time without finding real bugs." |
| The freeze lasts until 2027 while Google redesigns how it accepts security disclosures. | supported | Page 2: "The freeze lasts until 2027 while Google redesigns how it accepts security disclosures." |
| The supply-chain lane is still live. | supported | Page 2 comment by @peritumAI: "The supply-chain lane is still live." |
| Google just froze its open source bug bounty program because AI generated reports flooded it with junk. | supported | Page 3: "Google just froze its open source bug bounty program because AI generated reports flooded it with junk." |
| The model did not speed up security work. It created a slop filtering job nobody wanted. | supported | Page 3: "The model did not speed up security work. It created a slop filtering job nobody wanted." |
| Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports. | supported | Page 4: "Google has suspended product vulnerability submissions to its open-source bug bounty program until at least early 2027, after maintainers were overwhelmed by invalid AI-generated reports." |
| The pause took effect October 1 for product vulnerabilities in the OSS VRP | supported | Page 4: "The pause took effect October 1 for product vulnerabilities in the OSS VRP" |
| Supply-chain reports and some Google Cloud repos are still accepted | supported | Page 4: "Supply-chain reports and some Google Cloud repos are still accepted" |
| Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited | supported | Page 4: "Maintainers were flooded with thousands of reports describing bugs that didn't exist or couldn't be exploited" |
| Intel has also suspended its bounty program, which paid up to $100,000 per flaw | supported | Page 4: "Intel has also suspended its bounty program, which paid up to $100,000 per flaw" |
| As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027. | supported | Page 5: "As of Oct 1, Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program — with an update promised in Q1 2027." |
| Google stated its reason as 'a significant rise in automated submissions, the vast majority of which are not valid.' | supported | Page 5: "Its reason, in its own words: 'a significant rise in automated submissions, the vast majority of which are not valid.'" |
| Linux kernel maintainers got flooded by AI-generated CVE filings, with some releases hitting ~2,000. | supported | Page 5: "Linux kernel maintainers got flooded by AI-generated CVE filings — some releases hit ~2,000." |
| curl killed its bounty in January. | supported | Page 5: "curl killed its bounty in January." |
| HackerOne paused new Internet Bug Bounty submissions in March. | supported | Page 5: "HackerOne paused new Internet Bug Bounty submissions in March." |
| Intel quietly suspended its paid bounty — offering up to $100,000 a flaw — without giving a reason. | supported | Page 5: "Last month Intel quietly suspended its paid bounty — up to $100,000 a flaw — without giving a reason." |
| Google's own AI agent found 20 real vulnerabilities in open source last year. | supported | Page 5: "Google's own AI agent found 20 real vulnerabilities in open source last year." |