Google pauses open source bug bounty over flood of AI slop reports
Since October 1, Google's OSS VRP takes no new product vulnerability reports. Google blames a surge of automated submissions that were mostly invalid.

Google has paused a key part of its Open Source Software Vulnerability Reward Program (OSS VRP). Since October 1, the bug bounty no longer accepts new reports about product vulnerabilities in Google's open source projects. The reason, in Google's own words: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
What exactly is paused
The OSS VRP pays independent researchers for finding and responsibly reporting security flaws in Google's public repositories. The pause covers product vulnerability submissions, meaning code defects, logic flaws and design bugs. It does not cover everything:
- Reports submitted before October 1 are still handled.
- Supply chain reports under the OSS VRP are not affected.
- Some issues in Google Cloud repos can still go through the Cloud VRP.
Google announced the change on X and on the program website and promised an update in the first quarter of 2027. Until then, it points researchers to its other bug bounty programs.
Why it happened
Finding a real vulnerability used to take skill and hours of manual work. Large language models and automated bug hunting scripts have pushed the cost of filing a report close to zero. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by thousands of reports that looked plausible but turned out to be invalid, unexploitable or simply hallucinated. Every one of them still had to be checked by a human, which took time away from fixing real flaws.
Google is not alone. Tom's Hardware also points to Linux kernel maintainers who say they are swamped by AI driven bug reports, and to Intel suspending its own bug bounty program.
Why it matters
Bug bounties are one of the main ways open source software gets audited by outsiders. When the signal drowns in noise, programs close or get stricter, and honest researchers lose a channel and a source of income. The same AI tools that can genuinely help find bugs are now flooding the inbox that was meant to receive them. Expect more programs to add stricter rules, proof of exploit requirements or reputation gates.
Dany's take
This is AI slop with a real security cost. The tools are not the problem, unchecked output is. If you use AI to hunt bugs, verify every finding yourself before you hit submit. Otherwise the people who keep our software safe simply stop listening.
Source: TechCrunch, with details from Tom's Hardware.
Source: techcrunch.com