cd /news/ai-safety/google-pauses-open-source-bug-bounty… · home › topics › ai-safety › article
[ARTICLE · art-145011] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Google pauses open source bug bounty program as AI-generated reports pile up

Google is suspending new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) starting October 1, 2026, citing a flood of low-quality, AI-generated bug reports that contained hallucinations and described issues with negligible real-world impact. Reports filed before October 1 will still be processed, supply chain reports are unaffected, and certain Cloud-related submissions can still go through Google's Cloud VRP, with a formal update on revised submission rules expected in Q1 2027. Google had already raised the evidence bar for VRP submissions in March 2026, and the Internet Bug Bounty program, Intel, and Linux kernel maintainers have faced similar surges of questionable generative-AI-driven reports.

by read3 min views1 publishedOct 4, 2026
Google pauses open source bug bounty program as AI-generated reports pile up
Image: Cryptobriefing (auto-discovered)

Google / Wikimedia Commons (Public domain)

The company is suspending new product vulnerability submissions to its OSS VRP, citing a flood of low-quality automated reports that swamped human reviewers

Google has hit on part of its Open Source Software Vulnerability Reward Program. The reason is a flood of AI-generated bug reports.

Starting October 1, 2026, the company is no longer accepting new product vulnerability submissions to the program, known as the OSS VRP.

What Google is changing #

Google tied the suspension to a surge of low-quality, automated reports produced with AI tools. Those reports have been landing on security engineers and on the maintainers of open source projects.

According to Google, many of these submissions contained hallucinations. Others described issues with negligible real-world impact.

Most of the submissions in this surge turned out to be invalid. That is a problem because bug bounty programs rely on manual triage. A human has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability.

The is not a full shutdown. Here is how the cutoff works:

  • Reports filed before October 1 will continue to be processed without interruption.
  • Supply chain reports are not affected by the suspension.
  • Certain Cloud-related submissions can still be sent through Google’s Cloud VRP.

Google is also pointing researchers toward its other active reward programs while the OSS VRP is in place. It specifically mentioned its Patch Rewards program as an option.

AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

The company says it plans to revise how submissions work. A formal update on those reforms is expected in Q1 2027.

A problem Google already tried to fix #

This is not Google’s first attempt to manage the problem. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports. The changes raised the bar on the evidence researchers needed to provide.

Google also made changes to its reward programs for Android and Chrome during 2026. The OSS VRP suspension is the most aggressive step so far.

Google is far from alone. The Internet Bug Bounty program has run into the same issue. So have Intel and the maintainers of the Linux kernel, who have all dealt with rising volumes of questionable reports driven by generative AI.

Some of those programs have responded with s and adjustments of their own.

Why the bounty model is under strain #

Open source projects feel this most acutely. Many are maintained by small teams or volunteers who have no spare capacity to debunk hallucinated vulnerabilities. Google cited the burden on these maintainers directly in explaining the .

What this means #

For security researchers, the immediate effect is a narrower set of places to earn rewards from Google’s open source work. Legitimate researchers who find real flaws in open source products will need to look at other Google VRPs or the Patch Rewards program. The Q1 2027 update is the next marker to track. It will show whether Google believes the bounty model can be repaired with better rules, or whether open source security rewards need a different structure entirely.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/google-pauses-open-s…] indexed:0 read:3min 2026-10-04 · —