Skip to content
← All news
3 min read

Google pauses its open source bug bounty after a flood of invalid AI reports

Google stopped taking product vulnerability reports to its open source bounty on October 1, saying most automated submissions were not valid. Supply chain reports still count, and an update is due in Q1 2027.

Rewards ran from $100 to $31,337 for four years. On October 1, Google stopped taking most new reports.

On October 1, 2026, Google's bug bounty team posted a notice that its Open Source Software Vulnerability Reward Program (OSS VRP) is temporarily no longer accepting product vulnerability reports. The reason Google gave: "a significant rise in automated submissions, the vast majority of which are not valid." The change is now on the OSS VRP rules page, and Google has committed to an update in Q1 2027.

What stopped and what did not

The pause covers one category. Product vulnerabilities are bugs inside Google's own open source projects, such as Go, Angular, and Protocol Buffers, and those reports no longer go to the OSS VRP. Google's notice says supply chain reports are not affected, and neither are reports already in the queue. A report filed before October 1 still gets handled.

Google pointed researchers to its other reward programs and to the Patch Rewards Program instead. BleepingComputer reports that Patch Rewards pays up to $15,000 for high-impact fixes, and that bugs in Google Cloud open source repositories that affect Cloud products can still go through the Cloud VRP. Help Net Security notes the rules page still lists project tiers from OT0 to OT3, with no amounts shown for product vulnerabilities.

What the program paid

Google launched the OSS VRP in August 2022. At launch, BleepingComputer reported rewards from $100 to $31,337, set by severity and by how important the project is. The top awards went to Bazel, Angular, Golang, Protocol Buffers, and Fuchsia.

Across all its bounty programs, Google paid a record $17.1 million to more than 700 researchers in 2025, up from $12 million in 2024, according to BleepingComputer. So Google did not cite budget. It cited the share of reports that turned out to be wrong.

Google is not the first

In January, the curl maintainer ended the project's HackerOne bug bounty after a stream of AI slop reports, and in mid-September Intel removed financial rewards from its Intigriti program, BleepingComputer reports. In August we covered how Apple capped bug bounty submissions after a similar flood, and a real flaw nearly got stuck behind it.

The shape is the same each time. An AI tool makes a vulnerability report cheap to write. The cost of proving the report wrong lands on a maintainer or a triage team, and that cost does not shrink when the report was cheap.

What we do not know yet

Google has not published how many reports arrived, what share were invalid beyond "the vast majority", or what the reformatted program will require from researchers. The notice says Google will keep working on this part of the OSS VRP and give an update in Q1 2027. Until then, there is no announced reopening date for product vulnerability reports.

Why a build studio cares

Our audits use AI agents, so we produce the same kind of output Google is now refusing to read unfiltered. A Deep Audit runs three independent agent passes over a product, and a Full Audit has our engineers directing a fleet of ten agents. Agents find candidate issues fast. They also write confident paragraphs about flaws that are not there, which is exactly the report Google's triage team kept getting.

So agent output is a candidate list, not the report. A senior engineer checks each material finding against evidence before it reaches the severity-ranked findings: the request and response, the config value, the reproduction step. A finding we cannot back with evidence does not make the report. If a vendor or a tool hands you an AI-generated security report, ask the same thing of every finding: what evidence shows this is real?

Next step: read Google's notice and the OSS VRP rules, then watch for the Q1 2027 update. If an AI-generated security report landed on your desk and you cannot tell which findings are real, write to us at hello@gattyworks.com.

GoogleAI SecurityBug BountyGoogleBugBountyAISlopOSSVRPOpenSourceGoogleVRPSupplyChainSecurityAISecurityCybersecurityTechNews

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call