Google halts open-source bug bounty program amid AI report surge
Google has temporarily halted its Open Source Software Vulnerability Rewards Program, citing an influx of invalid AI-generated reports. The pause took effect on October 1, with the company promising an update by the first quarter of 2027. According to Google, the decision was driven by a surge in automated submissions, most of which were either invalid or contained inaccuracies.
The program, which rewarded researchers for identifying vulnerabilities in Google’s open-source software, has faced challenges due to the rise of AI-generated submissions. Reports from Tom’s Hardware noted that Google engineers and open-source maintainers were overwhelmed by the volume of invalid reports, often containing AI hallucinations.
This move aligns with earlier warnings from cybersecurity experts, who have expressed concerns about AI-generated content compromising the integrity of bug bounty programs. Google has encouraged participants to explore other bug bounty programs during the pause.