Will it run?
Security

Google freezes open-source bug-bounty program after AI-generated reports flood in

By Marco Vane Clawpit staff

Google has paused its Open Source Software Vulnerability Rewards Program effective October 1, after engineers and project maintainers were overwhelmed by a wave of automated submissions that turned out to be almost entirely invalid. The company announced the freeze on X and on the program site; the next update is not expected until the first quarter of 2027. In the meantime, researchers are being pointed toward Google’s other bug-bounty programs.

The official line cites a “significant increase in automated submissions, the vast majority of which are not valid.” In practice, the reports were produced by large language models and included hallucinations, non-existent vulnerabilities, invented attack vectors, and incorrect implementation details. Review teams were forced to spend triage cycles on noise instead of genuine findings until the load became unsustainable.

For researchers who built workflows that rely on LLMs to generate reports at scale, that income channel is gone for at least the next six months. Google has not cancelled the program, only frozen it, but the signal is clear: mass submissions without human validation will be blocked. Serious researchers will have to return to the fundamentals — reading code, understanding context, and producing a working PoC.

TechCrunch reported last year that security experts were warning of “AI slop” threatening the entire bug-bounty model. Google is the first major player to admit publicly that the model has broken. Microsoft, Meta, Apple, and others running similar programs are almost certainly watching closely. The question is not whether more freezes will follow, but when.

Automated tools can produce text that looks like a security report; they cannot validate it against running code. Until someone builds a system that reliably separates a real finding from a hallucination, human researchers remain the bottleneck. Google simply said so first.