SDSignal Desk

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Oct 4, 2026, 1:31 PM · TechCrunch

Image: TechCrunch

Google just paid the bill for AI slop in security research: its open-source bug bounty is frozen until 2027 because humans couldn’t keep up with automated junk reports.

Why it matters

Google has paused its Open Source Software Vulnerability Rewards Program, the bounty that paid researchers for finding flaws in the company’s open-source software. TechCrunch reports the pause took effect October 1, with Google promising an update in the first quarter of 2027 and pointing participants to its other bounty programs.

Google’s stated reason is a surge in automated submissions, “the vast majority of which are not valid.” Tom’s Hardware reported that Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations.

This is the warning security people have been sounding for a while, now made concrete by one of the biggest bounty operators on the internet. When the cost of filing a report drops to near zero, the cost lands on whoever has to read it.

From the desk

We want to be clear about what failed here, because it isn’t AI-assisted security research as such. Good tools that help researchers find and verify real bugs are a genuine public good. What broke Google’s program is volume without verification: people pointing models at codebases, pasting whatever comes out into a submission form, and hoping a payout sticks.

The asymmetry is brutal. A bad report takes seconds to generate and can take a skilled engineer an hour to disprove, especially when it’s written with the confident tone and plausible detail that hallucinated output does so well. Multiply that across a program and the triage queue becomes the attack surface. The people who pay are maintainers — often thinly staffed, often volunteers — who now spend their time debunking fiction instead of fixing code.

The downside of the freeze is real too. Legitimate researchers just lost a paying channel for open-source work, and the incentive to look hard at widely used projects drops while the program is dark. Real bugs don’t pause because the reward did. If other programs follow Google’s lead, the net effect of AI slop could be fewer eyes on critical software, not more.

Where this leads if it scales: bounty programs will have to put friction back in. I’d expect proof-of-concept requirements, reputation gates, deposits or rate limits on new submitters, and probably AI-assisted triage to fight AI-generated noise. That’s workable, but it tilts the field toward established researchers and away from the newcomers bounties were meant to welcome. The fix for cheap reports is expensive filters, and somebody pays for those.

I’m also watching who takes responsibility. The model makers can’t control every misuse, but tools that ship exploit-hunting agents should make verification the default, not an afterthought. A finding that hasn’t been reproduced isn’t a finding.

Context

TechCrunch reported last year that cybersecurity experts were warning AI-generated slop posed a serious risk to bug bounty programs. Google’s open-source program is the clearest case yet of that risk forcing a major program to stop paying out altogether.

Who feels it

Open-source maintainers
Short-term relief from junk triage, but less outside scrutiny of their code while the bounty is paused.
Security researchers
Legitimate hunters lose a reward channel until at least early 2027 and will likely face stricter submission rules when it returns.
Other bounty platforms
Google’s pause is a precedent; expect pressure to add proof requirements and filters before queues break.
AI tool builders
Security agents that don’t verify their own findings are now visibly costing the ecosystem, which invites both reputational and policy pushback.

What to watch

  1. Google’s promised Q1 2027 update and any new submission requirements it brings
  2. Whether other open-source or vendor bounty programs announce similar pauses or limits
  3. Proof-of-concept or reputation gates added by bounty platforms in response to automated reports

Read the original

Continue at the source.

TechCrunch

Companies: Google