Google froze its open source bug bounty program due to a 'significant rise' in AI submissions
AI-generated junk reports have overwhelmed Google's bug bounty program, signaling a systemic threat to open-source security incentives.
- 01AI-generated noise has forced Google to suspend its Open Source Software Vulnerability Rewards Program through at least Q1 2027.
- 02Engineers and maintainers were buried under invalid reports and hallucinated vulnerabilities.
- 03The pause confirms warnings security researchers raised last year: automated submissions degrade triage capacity, eroding the economics that make bug bounties viable.
- 04Google acknowledged the "vast majority" of recent submissions were not actionable.
AI-generated junk reports have overwhelmed Google's bug bounty program, signaling a systemic threat to open-source security incentives.
AI-generated noise has forced Google to suspend its Open Source Software Vulnerability Rewards Program through at least Q1 2027. Engineers and maintainers were buried under invalid reports and hallucinated vulnerabilities. The pause confirms warnings security researchers raised last year: automated submissions degrade triage capacity, eroding the economics that make bug bounties viable. Google acknowledged the "vast majority" of recent submissions were not actionable. - **Watch:** Whether Google's Q1 2027 update introduces AI-submission filters or stricter eligibility gates—and whether competitors face the same pressure.
Watch: How Google restructures eligibility rules in Q1 2027—its solution may set the industry standard for filtering AI-generated vulnerability reports.
Skip to content 08:18:27:51 Last day to exhibit your breakthrough to 10,000+ tech leaders at Disrupt is on Oct 2. Book Exhibit Table Now. Disrupt doors open Oct. 13.
Read the full article at techcrunch.comShow the full text · 2 min readHide the full text
Skip to content 08:18:27:51 Last day to exhibit your breakthrough to 10,000+ tech leaders at Disrupt is on Oct 2. Book Exhibit Table Now. Disrupt doors open Oct. 13. Get your pass and bring someone with you at 50% off. REGISTER NOW. Close TechCrunch Desktop LogoTechCrunch Mobile Logo Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Contact Us facebook.comtwitter.comlinkedin.comreddit.commailto:?subject=Google+froze+its+open+source+bug+bounty+program+due+to+a+%E2%80%98significant+rise%E2%80%99+in+AI+submissions&body=Article%3A+https%3A%2F%2Ftechcrunch.com%2F2026%2F10%2F04%2Fgoogle-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions%2Ftechcrunch.com In Brief Posted: 1:31 PM PDT · October 4, 2026 Image Credits:DBenitostock / Getty Images Anthony Ha Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year. Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software. In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said. In the meantime, participants are encouraged to consider Google’s other bug bounty programs. Topics AI, Security October 13 – 15 San Francisco Get 50% off a second pass The Disrupt experience is meant to be shared. Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem. BOOK NOW Newsletters See More Subscribe for the industry’s biggest tech news Related AI Can ‘super intelligence’ and a non-binding safety pact solve AI’s image problem? Anthony Ha 23 minutes ago Transportation TechCrunch Mobility: Reining in robotaxis Kirsten Korosec 4 hours ago AI Trump unveils his new Super Intelligence Force Anthony Ha 5 hours ago Latest in AI In Brief Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions Anthony Ha 7 seconds ago AI Can ‘super intelligence’ and a non-binding safety pact solve AI’s image problem? Anthony Ha 23 minutes ago AI Trump unveils his new Super Intelligence Force Anthony Ha 5 hours ago ✕ techcrunch.com X LinkedIn Facebook Instagram youTube Mastodon Threads Bluesky © 2026 TechCrunch Media LLC. Some areas of this page may shift around if you resize the browser window. Be sure to check heading and document order.
Don't miss tomorrow's
The Daily Pulse in your inbox each morning — sourced and linked.
Trainings
The full course catalogue.
Outside-In Diagnostic
Enter a ticker for an outside-in read of a public company's working capital, cost efficiency and growth against peers, built from SEC filings and earnings calls, with an executive synthesis.
Ask KokoAI about AI
Cited answers across news, vendors & capabilities.