Google Freezes Open Source Bug Bounty After AI Report Surge

Google has frozen its Open Source Software Vulnerability Rewards Program starting October 1, 2026, due to an influx of automated, AI-generated bug reports that are largely invalid. According to antaranews.com, the tech giant took the action after engineers and open-source maintainers became overwhelmed by low-quality submissions containing hallucinations and non-existent code.

Why Google Halted Open Source Bug Bounties

The temporary suspension applies specifically to the Open Source Software Vulnerability Rewards Program (OSS VRP). Google announced the pause on social media and its program website, promising a status update in the first quarter of 2027. Vietnam.vn reported that submissions received prior to October 1 are still being processed normally, while open-source supply chain reporting related to package distribution continues to operate.

The rise of large language models and automated bug-hunting tools made generating vulnerability reports easier. However, lensahukum.co.id noted that many submissions arrived formatted professionally with file paths and technical arguments, but engineers found missing source code or paranoid AI hallucinations upon manual inspection.

The Cost of AI Slop on Engineering Teams

Verifying thousands of low-utility reports consumed valuable engineering hours. Inet.detik.com reported that Google first attempted to tackle the issue back in March 2026 by tightening rules, requiring empirical proof of concept via OSS-Fuzz, and reducing payouts for lower-priority projects. Despite those hurdles, the automated submissions continued to flood in.

Google identified two primary problems during the March 2026 surge. One involved AI hallucinations regarding how vulnerabilities could be exploited, while the other involved minor bugs, such as buffer overflows, that had no real security impact on project models.

Google Freezes Open Source Bug Bounty After AI Report Surge
Photo: vietnam.vn

Other software projects face similar pressures from AI-generated spam. Vietnam.vn pointed out that the curl project previously halted its HackerOne bug bounty after reporting that 95 percent of submissions were AI-generated trash, while Intel temporarily paused its program offering up to $100,000 per vulnerability.

Where Security Researchers Can Submit Reports Now

Google has not shut down all of its reward channels. Lensahukum.co.id stated that the company directs developers and security researchers toward other active initiatives. Product bugs, Google Cloud vulnerabilities, and patch rewards remain open through separate pathways while the open-source portal undergoes structural simplification.

Google specifically encourages researchers to “explore other VRP programs” or join the Patch Rewards Program for product bugs.

Google Freezes Open Source Bug Bounty After AI Report Surge
Photo: lensahukum.co.id

Pluang.com reported that Alphabet Inc. shares traded at $343.50 amid the announcement, reflecting strong market capitalization despite the administrative pause in the developer program. This price, recorded as of 03:41 WIB on October 5, 2026, rose 1.56% in one day and sits closer to the 52-week peak of $402.62 than the low of $236.59.

Frequently Asked Questions About the Google Bug Bounty Freeze

When did the Google open-source bug bounty suspension begin?

The suspension took effect on October 1, 2026, as announced by Google on its program website and social media channels.

When will the Open Source Software Vulnerability Rewards Program return?

Google stated it plans to provide an update regarding the future of the OSS VRP program during the first quarter of 2027.

Which bug bounty programs remain active at Google?

While the open-source software program is paused, Google Cloud VRP, the Patch Rewards Program, and other product-specific vulnerability reward channels continue to operate normally.