Skip to content

Google pauses its open-source bug bounty over AI reports

Google stopped taking OSS VRP bug reports on October 1 after a surge of AI-generated submissions, most of them invalid. An update is due in Q1 2027.

By Tech AI Wire Team

3 min read

XLinkedIn
Screenshot of Google's Bug Hunters page showing the rules of the Open Source Software Vulnerability Reward Program.

By the numbers

top OSS VRP reward since its 2022 launch
$31,337
Google paid to 700+ researchers in 2025
$17.1M
top Patch Rewards payout, still open
$15,000
when Google promises an update
Q1 2027

Google stopped accepting new vulnerability reports for its Open Source Software Vulnerability Reward Program, or OSS VRP, on October 1, 2026. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," Google said, as quoted by TechCrunch. The program pays outside researchers who find security bugs in Google's open-source projects. The freeze closes one of the main paid routes for reporting flaws in tools such as Go and Angular.

What Google paused and what stays open

A bug bounty pays people who find and report security flaws. Google's notice reads: "We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports." BleepingComputer and Help Net Security both quote it.

Supply chain reports cover the systems that build and ship the code, rather than bugs in the code itself. Here is where each route stands, according to BleepingComputer:

RouteStatus
New OSS VRP product vulnerability reportsPaused since October 1
OSS VRP supply chain reportsStill accepted
Reports already submittedStill handled
Google Patch Rewards ProgramOpen, up to $15,000 for high-impact fixes
Google Cloud VRPOpen

What the program covered

Google launched the OSS VRP in August 2022, with rewards from $100 to $31,337, BleepingComputer reports. It covers Go, Angular, Bazel, Protocol Buffers, Fuchsia and critical third-party code those projects depend on. Bazel is a build tool, Protocol Buffers is a data format for sending structured data between programs, and Fuchsia is an operating system.

Google's bounty spending has been climbing. It paid a record $17.1 million to more than 700 security researchers in 2025, according to BleepingComputer. That was a 40% increase on the $12 million it paid in 2024.

Why AI reports broke the system

An AI chatbot can write a bug report that looks convincing in seconds. Google says the vast majority of the automated reports it received were not valid. Each one still needs a person to read it and try to reproduce the bug.

TechCrunch notes that it warned in July 2025 that this kind of "AI slop" posed a serious risk to bug bounty programs. It has promised a new plan. Help Net Security quotes the company's pledge: "We will continue to reformat and work on this aspect of the OSS VRP." Google added that it will "commit to giving an update in Q1 2027."

Google is not the first to pull back

Two other well-known programs changed course this year, BleepingComputer reports:

ProgramChange
curlEnded its HackerOne bug bounty in January 2026 after a flood of AI-written reports
IntelRemoved financial rewards in mid-September 2026, without explaining why

AI tools can also find real flaws when a person checks the results. A 16-year-old's home-built AI tool helped expose a Microsoft analytics flaw, which earned him a $5,000 bounty.

What this means for developers

If you found a real bug in Go, Angular or another covered project, still report it. The paid route is closed, but the projects' normal security contacts still need to hear about flaws. If you can also write the fix, the Patch Rewards Program still pays up to $15,000.

If you hunt bugs with AI tools, check every finding by hand first. Reproduce it, confirm the impact, and cut anything you cannot prove. Unverified reports are the reason this program closed.

If you maintain an open-source project, expect the same flood to reach your security inbox. Ask for a working proof of concept and exact steps to reproduce before anyone spends time on triage. A short report template filters out much of the noise. Decide now whether your project pays for reports at all.

Watch for Google's update in the first quarter of 2027. The rules it picks will show how large programs plan to live with AI-written reports.

Sources

  1. Google froze its open source bug bounty program due to a 'significant rise' in AI submissions - TechCrunch
  2. Google halts open-source bug bounty program amid AI spam surge - BleepingComputer
  3. AI slop submissions force Google to freeze its open-source bug bounty - Help Net Security

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.