# Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

> Source: <https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/>
> Published: 2026-10-04 20:31:07+00:00

Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.

Last year, TechCrunch reported that [cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs](https://techcrunch.com/2025/07/24/ai-slop-and-fake-reports-are-exhausting-some-security-bug-bounties/). Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.

In posts [on X](https://x.com/GoogleVRP/status/2105689195180179605) and [the program website](https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules#reward-amounts), Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. [According to Tom’s Hardware](https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1), Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

In the meantime, participants are encouraged to consider Google’s other bug bounty programs.
