Google has paused its Open Source Software Vulnerability Rewards Program, the initiative that pays security researchers for finding vulnerabilities in the company's open-source projects, blaming a surge of automated, largely useless submissions. The pause took effect on October 1, and Google says participants can expect an update in the first quarter of 2027.
The announcement was posted on X and on the program's own website, where Google gave an unusually blunt explanation for the shutdown. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said. In other words, the pipeline of reports has not slowed down — it has been drowned in noise, and almost none of that noise is human. For more coverage of how generative tools are reshaping the software ecosystem, see our latest AI developments.
What the paused program actually does
The Open Source Software Vulnerability Rewards Program, usually shortened to OSS VRP, is Google's vehicle for rewarding outside researchers who find security flaws in the open-source code the company releases and maintains. Rather than limiting bounties to Google's proprietary products, the program extends payouts to vulnerabilities discovered in open-source projects, on the theory that the security community will find bugs faster if there is an incentive attached.
That model only works when the signal-to-noise ratio is manageable. A small team of program reviewers has to triage every incoming report, reproduce the claimed vulnerability, judge its severity, and decide on a reward. Every invalid report consumes the same staff time as a real one, and unlike a real one, it produces nothing in return.
Engineers are drowning in hallucinated findings
The operational reality behind Google's announcement was reported in more detail by Tom's Hardware, which found that Google engineers and open-source maintainers had been overwhelmed by reports that were invalid or contained outright hallucinations. That is the signature failure mode of AI-assisted vulnerability research: a language model can generate a report that looks formally correct — complete with affected components, reproduction steps, and impact analysis — while describing a bug that simply does not exist.
Triaging such a submission is not a ten-second dismissal. A reviewer has to read the report, check the claimed code path, and verify that the flaw is bogus before rejecting it. Multiply that by a flood of automated submissions and the economics of the entire program collapse. The bounty program, designed to amplify human researchers, becomes a denial-of-service attack against the very reviewers it was meant to work with.
The warning arrived a year early
The pause did not come out of nowhere. TechCrunch noted that it reported last year on cybersecurity experts warning that AI slop posed a serious risk to bug bounty programs. The prediction was straightforward: as generative models made it nearly free to produce plausible-looking technical documents, the cost of submitting a fake or low-quality report would drop to zero, while the cost of reviewing it stayed the same.
That asymmetry is now playing out at one of the largest technology companies in the world. Bug bounty platforms across the industry have been experimenting with countermeasures — stricter submission requirements, proof-of-work requirements, reputation systems — but Google has chosen the bluntest instrument available: stop accepting reports entirely until the intake problem is solved.
What happens to researchers in the meantime
Google's message to participants is to redirect their efforts. In the interim, researchers are being encouraged to consider the company's other bug bounty programs, which cover Google's flagship products and appear to be operating normally. The OSS VRP itself is promised an update in the first quarter of 2027, though Google has not said what form that update will take — new submission filters, identity verification, AI-assisted triage, or a redesigned reward structure are all plausible directions, but the company has committed to none of them publicly.
For legitimate security researchers, the freeze is a real cost. Work on an open-source vulnerability discovered before October 1 now sits in limbo, and there is no indication whether Google will honor reports submitted near the cutoff or ask submitters to resubmit after the relaunch.
A stress test for open-source maintenance
The deeper story here is about the economics of open-source maintenance. Volunteer maintainers already struggle with the volume of feature requests, pull requests, and issue reports generated by human users. AI-generated content raises that baseline load across every channel at once: bug reports, security disclosures, documentation questions, and code contributions can all now be produced at industrial scale by actors with no stake in the project's actual health.
Google's response — closing the doors of a security program entirely — is the kind of measure that would have seemed disproportionate eighteen months ago. The company's own framing, that the vast majority of automated submissions are invalid, suggests the intake problem grew faster than any filtering approach could absorb. Whether a Q1 2027 relaunch can restore a workable signal-to-noise ratio will say a lot about whether bug bounty programs, as an institution, can survive the era of free text generation.
Until then, the message to the security research community is a frustrating one: the vulnerabilities are still out there, the rewards are still theoretically on the table, but Google is not currently accepting help finding them.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →