Threat assessment: high. Google has paused its Open Source Software Vulnerability Rewards Program. The company blames a “significant rise” in AI-generated submissions, most of which turned out to be useless. TechCrunch AI reports the freeze took effect on October 1, and Google has promised “an update” in the first quarter of 2027.
So for at least the next few months, one of the biggest open source bug bounty programs is offline. AI-generated junk is the reason.
🎯 Situation Report
Here’s what we know:
- What: Google’s open source bug bounty paid researchers for finding vulnerabilities in the company’s open source software. It’s now suspended.
- When: The pause started October 1. Google says it’ll share more in Q1 2027.
- Why: Google says in its own words, “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
- Who got hurt: According to Tom’s Hardware, as cited by TechCrunch AI, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
- What’s still open: Google is pointing participants to its other bug bounty programs, which are still running.
⚠️ Why This Matters
People saw this coming. Last year, TechCrunch reported that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs. Now one of the most well-funded security programs in tech has hit the brakes.
The math is simple. An AI tool can produce a convincing vulnerability report in seconds. Checking that report still takes a skilled human, sometimes for hours. If you pay for valid findings and spamming costs almost nothing, people will spam.
The hallucination part is what really hurts. A fake report doesn’t just waste time. It can look completely real. It cites functions, describes attack paths, and sounds technical. A maintainer has to dig into the code to prove that something doesn’t exist, and that’s exhausting work.
The burden also lands unevenly. Google can absorb some wasted engineering hours. Volunteer open source maintainers, many of them unpaid, can’t. Every bogus report pulls them away from real fixes and real security work.
🔍 The Bigger Picture
This isn’t only Google’s problem. Open source maintainers have been complaining publicly about AI-generated bug reports for a while. The curl project’s maintainers have been among the loudest critics of low-quality, AI-written security submissions.
What stands out is the scale. When a company with Google’s resources decides it can’t triage the flood, smaller programs should take note. If Google can’t filter it efficiently, most organizations won’t be able to either.
There’s an irony here too. AI really can help find vulnerabilities, and good researchers use it well. The tool isn’t the problem. The problem is people running AI to mass-produce submissions that nobody checks before sending.
🛡️ Tactical Implications
What practitioners should watch for:
- Stricter submission rules. Expect bounty programs to require working proof-of-concept exploits, reproducible steps, or verified identities before anyone looks at a report.
- Reputation gating. Platforms may limit access to researchers with a track record of valid findings. That makes it harder for newcomers to break in.
- AI disclosure policies. More programs may ask researchers to say whether AI helped produce a report, or ban unreviewed AI output outright.
- Penalties for junk. Look for account bans or reputation hits for repeat invalid submissions.
- AI triage tools. Companies will probably turn AI on the problem itself, using models to screen incoming reports. That’s an arms race, and it won’t be clean.
If you’re a legitimate security researcher, this hurts you most. The people who used Google’s program properly just lost an income stream and a way to build a reputation because of other people’s spam.
📡 What Comes Next
Google’s Q1 2027 update will be worth watching. The company could relaunch with tighter rules, change how rewards work, or quietly fold the program into its other bounty efforts. Whatever it picks will likely become a template for the rest of the industry.
The bigger lesson for anyone running an open submission system is that if AI makes contributing cheap, the cost moves to whoever has to review it. Bug bounties are just the first place where that bill came due in public.
Full details are available in the original TechCrunch AI report.