Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
- ID
- 31694
- Status
- summarized
- Published
- 05 Oct 2026, 4:31 AM
- Fetched
- 05 Oct 2026, 4:39 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 7.0
- Created
- 05 Oct 2026, 4:40 AM
- Tags
- Audience
- developersai_agent_usersai_ml_learners
What happened
Google paused its Open Source Software Vulnerability Rewards Program as of October 1, with a promised update in Q1 2027, citing a "significant rise in automated submissions, the vast majority of which are not valid." According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations, and TechCrunch notes prior warnings from cybersecurity experts that AI slop posed a risk to bug bounty programs. Participants are pointed to Google's other bug bounty programs in the meantime.
Why it matters
If you maintain open source code or triage inbound reports, this is a concrete data point that AI-generated submissions can overwhelm a review pipeline badly enough to shut down a paid program for two quarters — plan for verification-first intake (reproduction steps, rate limits, human screening) rather than trusting volume. If you file findings against Google's open source projects, the OSS VR Program pays nothing until at least Q1 2027, so route them to Google's other bounty programs instead. Builders shipping agentic security scanners should treat validity filtering, not scanning, as the hard part.
Discussion angle
Google shut a paid program rather than keep triaging AI submissions — what intake rules (proof-of-concept requirements, per-submitter rate limits, automated dedupe) would have kept it open, and would those same rules work for your own issue tracker or PR queue?