Google Pauses Open Source Bug Bounty Over Invalid AI Reports
Google paused its open source bug bounty after AI-driven reports surged, with most submissions invalid. An update is due in the first quarter of 2027.
Summary
As of October 4, 2026, Google’s Open Source Software Vulnerability Rewards Program has been paused since October 1 following a significant increase in automated AI submissions. Google said the vast majority were invalid, while hallucinated reports overwhelmed its engineers and open source maintainers. The program rewards researchers for finding vulnerabilities in Google’s open source software.
Google will provide an update in the first quarter of 2027 but has not announced a firm reopening date. Until then, researchers cannot submit through this program and are encouraged to use Google’s other bug bounty programs.
Positives
- A first-quarter 2027 update gives researchers a defined checkpoint for news about the paused program.
- Google’s other bug bounty programs remain available to participants during the Open Source program’s suspension.
- The Open Source Software Vulnerability Rewards Program has rewarded researchers for finding flaws in Google’s open source software.
Risks & concerns
- The October 1 freeze removes a reward channel for researchers finding vulnerabilities in Google’s open source software.
- Google said the vast majority of the increased automated submissions were invalid.
- Invalid and hallucinated reports overwhelmed Google engineers and open source maintainers.
- Google has promised a first-quarter 2027 update but has not set a firm reopening date.