NEWS

Google Halts Open Source Bug Bounty Program Amid AI Spam Surge

Google paused OSS VRP product submissions on October 1 after AI-generated reports buried reviewers, joining curl and Intel in scaling back bounties.

Dylan H.

News Desk

October 5, 2026
8 min read
Google Halts Open Source Bug Bounty Program Amid AI Spam Surge

Google Suspends Open Source Bug Bounty Submissions as AI-Generated Reports Overwhelm Reviewers

Google has suspended product vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026, after a flood of AI-generated reports — the vast majority invalid — overwhelmed the engineers and maintainers who triage them. The company's OSS VRP rules page now states plainly that "as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP," citing "a significant rise in automated submissions, the vast majority of which are not valid." Google described the influx as thousands of low-effort, poorly written submissions — many containing outright hallucinations — that diverted staff time away from genuine vulnerability reports.


Details

AttributeValue
ProgramOpen Source Software Vulnerability Rewards Program (OSS VRP)
OperatorGoogle
LaunchedAugust 2022
Reward range$100 – $31,337
Covered projectsGolang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies
Suspension effectiveOctober 1, 2026
Scope of suspensionProduct vulnerability submissions only
UnaffectedSupply chain reports; reports filed before October 1
Still openPatch Rewards Program (up to $15,000); Cloud VRP for Google Cloud open-source repos
Stated reasonSurge in automated, largely invalid submissions
Resolution timelineFormal update promised Q1 2027

What Happened

A Flood of Low-Quality, AI-Generated Reports

Google said the pause was driven by a sharp rise in automated submissions — reports generated or heavily assisted by large language models (LLMs) pointed at public repositories and asked to produce a plausible-sounding vulnerability writeup. According to Google, "the vast majority" of these were not valid: many contained hallucinated vulnerabilities that did not exist in the code at all, while others described real but negligible-impact issues dressed up to look critical. Because bug bounty triage is fundamentally a manual process — a human has to read each report, attempt to reproduce the described flaw, and render a judgment — the submission cost for an attacker (or an overeager researcher running an AI tool) dropped to near zero while the triage cost for Google's engineers stayed exactly where it was.

What's Paused and What Isn't

The suspension is narrowly scoped to product vulnerability submissions under OSS VRP. Google explicitly clarified: "This does not impact OSS VRP supply chain reports, or any outstanding reports." Reports filed before October 1 will continue to be processed without interruption, and supply chain disclosures — which cover compromised dependencies, build pipelines, and distribution infrastructure rather than code-level bugs — remain open. Researchers can still pursue rewards through two adjacent channels: the Google Patch Rewards Program, which pays up to $15,000 for high-impact fixes to open-source software, and the Cloud VRP, which covers vulnerabilities in Google Cloud's open-source repositories.

Google's Plan to Reopen

Google says it is now working on restructuring OSS VRP to filter out automated, low-quality submissions before they reach human reviewers, though it has not detailed what that will look like. The company has committed to providing a formal update on the redesigned program during the first quarter of 2027 — meaning the open-source community faces roughly a quarter without a financially incentivized channel for reporting product-level vulnerabilities in Google's open-source projects.

Not an Isolated Incident

Google's move is the latest in a string of bug bounty operators buckling under AI slop in 2026. The curl project ended its HackerOne bounty entirely on January 31, 2026, after founder Daniel Stenberg found the confirmed-vulnerability rate had collapsed from historically above 15% to under 5%, with roughly 20% of all 2025 submissions assessed as AI-generated noise. In the first 21 days of 2026 alone, curl received 20 submissions — seven of them within a single 16-hour window — and none identified a real vulnerability. Stenberg's instant-ban policy for AI-generated reports, introduced in May 2025, did not stem the tide; by July 2025 submission volume had spiked to eight times the program's normal rate. "Not only the volume goes up, the quality goes down," Stenberg said. "So we spend more time than ever to get less out of it than ever." Intel suspended its own paid bug bounty — which had offered up to $100,000 per flaw — on September 19, 2026, replacing it with a no-reward Intigriti responsible-disclosure program amid suspicion that automated submissions drove the change. Linux kernel maintainers have separately reported being "completely overwhelmed" by AI-generated CVE filings, with some release cycles logging as many as 2,000 reported vulnerabilities, and cited false AI-generated bug reports as a factor in ending support for some older network drivers. In response, the Linux Foundation announced a $12.5 million initiative in March 2026, backed by Anthropic, AWS, GitHub, Google, Microsoft, and OpenAI, to help open-source projects manage the surge.

Impact Assessment

Impact AreaDescription
Open-source vulnerability disclosureNo financially incentivized channel for product-level OSS VRP reports until at least Q1 2027
Maintainer and engineer workloadTriage capacity previously consumed by AI slop can redirect to supply chain reports and legitimate backlog
Security researcher communityLegitimate researchers lose a rewards channel; may shift effort to Patch Rewards or Cloud VRP instead
Bug bounty industryReinforces a 2026 pattern (curl, Intel, now Google) of programs curbing or ending rewards over AI-generated noise
Open-source project trustRisk that real, novel vulnerabilities in Golang, Angular, Bazel, and similar projects go unreported longer
AI tooling accountabilityIncreases pressure on AI vendors and researchers to build validation/reproduction steps into automated scanning workflows

Recommendations

For Security Researchers

Do not submit AI-generated vulnerability reports to OSS VRP without independently reproducing the described flaw end-to-end. Programs across the industry are now instituting bans and public call-outs for low-effort, unverified submissions; treat any LLM output as a starting hypothesis, not a finished report. Until Google reopens OSS VRP in 2027, route legitimate Golang, Angular, Bazel, Protocol Buffers, or Fuchsia findings through the Patch Rewards Program or standard responsible-disclosure channels if a paid report isn't available.

For Open-Source Maintainers

Evaluate whether your project's own disclosure intake needs similar safeguards — rate limiting, mandatory proof-of-concept reproduction steps, or an explicit AI-disclosure policy — before a similar flood arrives. Consider engaging with the Linux Foundation's $12.5 million triage-tooling initiative if your project is affected by automated-report volume.

For Enterprise Security Teams

Do not assume OSS VRP's pause reduces your exposure: vulnerabilities in Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and Google's other open-source dependencies can still be discovered and disclosed outside the program, including irresponsibly. Maintain active monitoring of upstream advisories for projects you depend on, and don't rely solely on Google's bounty pipeline as a vulnerability early-warning system during the pause.

For AI Tool Vendors and Researchers

Build reproduction and validation gates into automated vulnerability-scanning tools before output reaches a human submission form. The pattern across curl, Intel, and now Google suggests unverified LLM output at scale is actively degrading the usefulness of bug bounty programs industry-wide — a problem the AI tooling ecosystem has a direct stake in fixing.

Key Takeaways

  1. Google suspended OSS VRP product vulnerability submissions on October 1, 2026, citing a flood of automated reports where "the vast majority" were invalid or hallucinated.
  2. The pause is scoped to product vulnerabilities only — supply chain reports and pre-October 1 submissions continue to be processed normally.
  3. Alternative paid channels remain open: the Patch Rewards Program (up to $15,000) and the Cloud VRP for Google Cloud open-source repos.
  4. Google has committed to a formal update on a restructured OSS VRP in Q1 2027, leaving a roughly three-month gap with no incentivized reporting channel for product bugs.
  5. Google joins curl (ended its bounty January 31, 2026, confirmed-vulnerability rate under 5%) and Intel (suspended its paid program September 19, 2026) as major 2026 casualties of AI-generated bug report spam.
  6. The Linux Foundation's $12.5 million initiative, backed by Anthropic, AWS, GitHub, Google, Microsoft, and OpenAI, signals the industry now treats AI slop triage as a shared infrastructure problem, not a single vendor's headache.

Sources