Skip to main content

Google Pauses Open Source Bug Bounty Over AI Spam

Google has temporarily frozen its open-source vulnerability rewards program until early 2027 due to a surge of invalid AI-generated submissions.

AI-written
Inewgen
05 Oct 2026Source: TechCrunch2 min read (0 views)
Share
Google Pauses Open Source Bug Bounty Over AI Spam

Stock photo for illustration only, not from the actual event

Font size
  • Google freezes its open source bug bounty program until early 2027
  • The pause is driven by a massive influx of automated AI submissions
  • Engineers and maintainers were overwhelmed by invalid reports and hallucinations

Google has officially decided to pause its Open Source Software Vulnerability Rewards Program, which rewards researchers for identifying security flaws in the company's open-source software. The suspension took effect on October 1, with a promise from the tech giant to provide a program update in the first quarter of 2027.

This move follows warnings previously highlighted by cybersecurity experts regarding the serious risks that low-quality AI-generated content poses to structured bug bounty initiatives across the industry.

business conference seminar meeting room presentation

Stock photo for illustration only, not from the actual event

In official statements shared on X and the program's dedicated website, the company elaborated on the core driver behind the temporary shutdown:

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid"

Google

According to reports from Tom's Hardware, Google engineers alongside open-source maintainers found themselves completely overwhelmed by an avalanche of incoming reports that either lacked validity or suffered from AI hallucinations.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

Analysis: Google's predicament highlights a growing challenge for platform security teams as automated tools make it effortless to generate mass submissions. When bad actors or misguided users flood reporting pipelines with AI-generated noise, it drains critical engineering hours. Other major tech platforms may soon need to adopt advanced filtering mechanisms to protect their review processes from similar automated spam.

In the interim, participants looking to report vulnerabilities are encouraged to explore Google's remaining active bug bounty programs while the open-source initiative remains frozen.

Source: TechCrunch

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article