AI NewsDev toolsReported

Google paused its open-source bug bounty program on 1 October after AI-generated submissions overwhelmed its engineers

Google stopped taking product vulnerability reports to its Open Source Software VRP on 1 October 2026, saying automated submissions, most of them invalid, had risen sharply, and promised an update in the first quarter of 2027.

AI News

Editorial2 min read

LinkedInX

Why it mattersA bug bounty maintained by Google is now closed to new product reports for at least three months, so anyone who runs or submits to this program needs an alternative route and should expect other OSS maintainers to tighten their intake the same way.

Google has stopped paying for bug reports against its open-source projects, because so many of the reports now come from a language model and describe a vulnerability that is not there. The company said on 1 October 2026 that its Open Source Software Vulnerability Rewards Program will not accept new product submissions, and promised an update in the first quarter of 2027.

The Google VRP account posted on X: "PSA for open-source bug hunters. We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRPs." TechCrunch and Tom's Hardware both reported the pause the same week, and TechCrunch quoted Google's stated reason: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

What is paused and what is not

The program was first announced in August 2022 to reward reports against Google-maintained open-source projects such as Bazel, Angular, Golang, Protocol Buffers and Fuchsia. The pause covers new product vulnerability submissions. Three things keep working. Any report filed before 1 October will still be processed. Supply chain submissions, which cover compromised build systems and tampered packages, remain open. Researchers who found a product bug in a Google Cloud repository can still send it through the Cloud VRP instead.

Google did not publish a per-week or per-month count of the automated submissions it is receiving, and the two reporting outlets did not have one either. The company's own description is "a significant rise" and that most of the reports contain hallucinations or describe issues with no real-world impact.

Why this is not only Google's problem

Open-source maintainers outside Google have been saying the same thing in public for over a year. The pattern is a report that reads like a competent write-up, cites a real file and function, and describes a vulnerability that does not exist in the code. A human then spends an hour confirming nothing is wrong. For an unpaid maintainer the time cost is the whole burden, and for a paid program the time cost falls on the engineers who triage.

A paused bounty program is the first visible step from a large maintainer. A quieter step, already common in smaller projects, is a policy that rejects AI-assisted reports on arrival. Expect more of either over the next few months. If a team at a software company runs its own bug bounty or security disclosure channel, the triage queue is where this story lands first.

Anyone who was planning to submit to Google's OSS VRP in Q4 2026 should route the report somewhere else. Google's Cloud VRP covers some overlap. The project's own GitHub Security Advisory channel takes a report that will reach the maintainer directly, without a reward attached but also without a queue of AI slop ahead of it.

Source

Primary source: Google VRP on X, 1 October 2026. Reporting: TechCrunch, Anthony Ha, 4 October 2026. Program background: OSS VRP rules, Google Bug Hunters.

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX