{"slug": "google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai", "title": "Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions", "summary": "Google paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a \"significant rise in automated submissions, the vast majority of which are not valid,\" with an update promised in the first quarter of 2027. Google engineers and open source maintainers were overwhelmed by invalid or hallucinated AI-generated bug reports, according to Tom's Hardware. Participants were directed to Google's other bug bounty programs while the open source program remains suspended.", "body_md": "Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.\n\nLast year, TechCrunch reported that [cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs](https://techcrunch.com/2025/07/24/ai-slop-and-fake-reports-are-exhausting-some-security-bug-bounties/). Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.\n\nIn posts [on X](https://x.com/GoogleVRP/status/2105689195180179605) and [the program website](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules#reward-amounts), Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. [According to Tom’s Hardware](https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1), Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.\n\n“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.\n\nIn the meantime, participants are encouraged to consider Google’s other bug bounty programs.", "url": "https://wpnews.pro/news/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai", "canonical_source": "https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/", "published_at": "2026-10-04 20:31:07+00:00", "updated_at": "2026-10-04 20:42:31.043917+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence"], "entities": ["Google", "Open Source Software Vulnerability Rewards Program", "Tom's Hardware", "TechCrunch"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai", "markdown": "https://wpnews.pro/news/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai.md", "text": "https://wpnews.pro/news/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai.txt", "jsonld": "https://wpnews.pro/news/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai.jsonld"}}