Google Pauses Open Source Bug Bounty Program Amid AI Submission Surge
Google has temporarily suspended its Open Source Software Vulnerability Rewards Program effective October 1, citing a substantial increase in automated, AI-generated security submissions. The decision halts the platform, which previously compensated independent researchers for identifying flaws in the company’s open source projects. According to official program announcements, the vast majority of recent automated reports contained invalid data or AI-driven hallucinations, overwhelming engineering teams and open source maintainers who struggled to triage and validate the influx. The suspension will remain in place until Google provides a formal program update in the first quarter of 2027. During the interim, security researchers are being directed to participate in Google’s other active bounty initiatives. The pause validates longstanding industry warnings regarding the vulnerability of crowdsourced security programs to synthetic traffic, a risk previously highlighted by cybersecurity analysts concerned about the degradation of program integrity by automated tools. By implementing this temporary freeze, Google aims to restore the signal-to-noise ratio and preserve the efficacy of its vulnerability disclosure framework before restructuring its intake mechanisms for future research workflows.
