Google Pauses Open Source Bug Bounty Program Over AI Slop
Google paused its Open Source Software Vulnerability Rewards Program after a surge of invalid, AI-generated submissions overwhelmed its engineers.
Google paused its Open Source Software Vulnerability Rewards Program on October 1, 2026, citing an overwhelming surge of invalid submissions. The company attributed the disruption to a rise in AI-generated reports, which it described as AI slop, noting that the vast majority of these submissions contained hallucinations or failed to meet program criteria.
This influx of automated reports overwhelmed both company engineers and open source maintainers, making it difficult to maintain the integrity of the reward system. While the open source program is frozen, the company continues to encourage researchers to participate in its other existing bug bounty programs.
Google has not announced a replacement for the specific open source program but intends to provide a formal update in the first quarter of 2027. The company stated it remains committed to improving software security and exploring new methods to address vulnerabilities in its products.