AI RACE— The AI Race
Business

Google Freezes Open Source Bug Bounty Program Over Surge in Flawed AI Submissions

Google has paused its Open Source Software Vulnerability Rewards Program until 2027 after receiving a flood of invalid, AI-generated bug submissions and hallucinations.

10/05/2026, 03:31
Business

Google has suspended its open source bug bounty program, attributing the decision to an overwhelming volume of low-quality, automated vulnerability reports generated by artificial intelligence.

The suspension of the Open Source Software Vulnerability Rewards Program officially took effect on October 1. The initiative, which rewards security researchers for identifying vulnerabilities across Google’s open source projects, will remain on hold while the company evaluates the program. Google announced on its website and on X that it plans to provide an update in the first quarter of 2027.

Overwhelmed by Automated Hallucinations

Google confirmed that the flood of automated submissions forced its hand, noting that the vast majority of incoming reports lacked merit.

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company stated.

Reports from Tom's Hardware indicate that Google engineers and open source maintainers have struggled under the administrative burden of sorting through the invalid claims, many of which contained fabricated details or hallucinations typical of generative AI tools.

A Growing Challenge for Security Programs

The incident highlights a broader issue in the cybersecurity landscape. Industry experts have previously raised alarms about the threat of "AI slop" degrading crowdsourced security initiatives. As automated tools make it trivial to generate and submit hundreds of convincing-looking flaw reports, human triage teams face mounting backlogs of inaccurate or unverified vulnerabilities.

In the meantime, Google stated that researchers looking to report vulnerabilities should direct their efforts toward the company's other active bug bounty programs.

◗ Sources

TechCrunch10/05

Related stories