Google pauses bug bounty program amid AI-driven spam surge
Google has temporarily halted its Open Source Software Vulnerability Rewards Program (OSS VRP) due to an overwhelming surge of invalid, AI-generated submissions. The company cited a significant rise in automated reports that were often bogus or irrelevant, making the program unmanageable. This pause, announced on October 1, 2026, will last until the end of the year, during which Google plans to reassess and reform the process.
While AI has accelerated vulnerability discovery, it has also introduced challenges. Frontier models like Mythos and GPT-5.6-Cyber have enabled companies to identify vulnerabilities faster, but many findings are flawed or hallucinated. For instance, Microsoft's Patch Tuesday saw a dramatic increase in patched flaws after adopting AI tools, but research from 1Passwords Off-by-1 Labs found that nearly half of AI-generated patches failed to fully address issues.
Google is not alone in facing these issues. In January 2026, the developers of curl ended their HackerOne bug bounty program due to similar problems. Later, in May, Linux lead maintainer Linus Torvalds described the security mailing list as "almost entirely unmanageable" because of AI-driven spam. These incidents highlight the growing pains of integrating AI into cybersecurity efforts.
Google encouraged researchers to submit findings through other VRP programs or the Patch Rewards Program during the pause. The company promised to provide an update in Q1 2027 as it works to improve the OSS VRP process.