Google Suspends Open Source Bug Bounty Program Over AI Spam Surge
Google has suspended its Open Source Software Vulnerability Rewards Program after a massive influx of automated, largely invalid bug reports generated by artificial intelligence. The shutdown took effect on October 1, 2026, as engineers and maintainers grew overwhelmed by artificial intelligence-generated submissions, ANTARA News reported. The company announced it will pause the program to streamline processes and provide an update in the first quarter of 2027.
While automated scanners and large language models help security researchers discover legitimate software flaws, they also unleash a wave of low-quality submissions that consume valuable engineering hours. Open source maintainers and corporate security teams now find themselves sorting through automated noise rather than patching critical threats.
Engineers Overwhelmed by AI Hallucinations and Automated Noise
The primary driver behind Google’s suspension is the sheer volume of invalid submissions flooding its triage pipeline. According to TechCrunch reporting cited by ANTARA News, Google engineers and open source maintainers faced overwhelming volumes of automated reports containing artificial intelligence hallucinations. Google formally stated that the pause stems from a significant increase in automated filings that lacked valid security impact.
LensaHukum.co.id and Detik iNET reported that the platform struggled with two distinct problems since early 2026. First, automated systems produced sophisticated-looking reports featuring technical arguments and file paths that referenced nonexistent source code or hallucinated exploit paths. Second, researchers submitted valid code anomalies, such as minor buffer overflows, that carried no actual security impact because the affected code remained unreachable or irrelevant to project safety models.

Google attempted to counter the trend earlier in the year by tightening program requirements. In March 2026, the company forced contributors to provide clear empirical proof, such as reproduction evidence using OSS-Fuzz, and reduced payouts for lower-priority projects. Despite these restrictions, the automated flood continued unabated, forcing the tech giant to shutter the portal entirely.
Broader Industry Impact Across the Open Source Ecosystem
Google is not alone in grappling with automated vulnerability spam. The open source project curl previously halted its HackerOne bug bounty program after discovering that 95 percent of reports received in 2025 consisted of AI-generated garbage.
Linux maintainers reported facing similar surges in questionable vulnerability claims, while Intel temporarily paused its bug bounty program—which previously offered up to $100,000 per vulnerability—amid mounting industry pressure.
Google maintains alternative security reporting channels
Despite the freeze on the Open Source Software Vulnerability Rewards Program, Google maintains other security channels. Google encourages security researchers to redirect product bug reports toward its separate Vulnerability Reward Program, Patch Rewards, or Cloud VRP for issues impacting Google Cloud.
Google will update open source bug bounty status in 2027
When will Google resume its open source bug bounty program?
Google plans to provide an update on the future of the Open Source Software Vulnerability Rewards Program during the first quarter of 2027.

What specific security program was suspended?
Google paused its Open Source Software Vulnerability Rewards Program (OSS VRP), which offered cash rewards to researchers finding security flaws in Google open source projects.
Are other Google security reporting programs also shut down?
No. Google’s product bug rewards, Cloud VRP, and the Patch Rewards program remain active, and supply chain packaging security reporting continues to operate normally.
Why did the automated reports fail validation?
Google engineers found that automated submissions frequently included AI hallucinations regarding exploit methods or highlighted minor code errors with no actual security impact.
Worth a look