adtestbench

AI news · Google · security

Google pauses open-source bug bounty over AI-made reports

Product flaw reports to Google’s open-source reward programme are on hold after a flood of invalid AI-generated submissions.

By Alexandre S. , 05:40 UTC

Google has stopped accepting product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP) since 1 October 2026, after thousands of low-quality, AI-generated submissions, Tom’s Hardware reported on Saturday 3 October. Many of the reports described flaws that did not exist or could not be exploited, and maintainers lost hours to triage that could have gone on repairs.

Retro-futurist illustration: a striped sunset over a grid horizon under a starry sky, with a security shield with a padlock standing on the horizon.
Drawn by adtestbench from “Google freezes open-source bug bounty program amid flood of invalid AI slop submissions”,

The pause is partial. Reports filed before 1 October are unaffected, supply-chain reports to the programme continue, and Google’s Cloud VRP covers some Google Cloud repositories. Google has committed to an update by the first quarter of 2027 while it reworks this part of the programme, according to Tom’s Hardware.

The programme launched in 2022 and paid between $100 and $31,337 per report, Hardware Busters notes, adding that a Google AI agent has itself found 20 real flaws in open-source code. Tom’s Hardware adds that Intel has suspended a bounty that paid up to $100,000 per flaw, and that Linux maintainers report record numbers of CVE findings per release.

For teams that buy AI security tools, the lesson is in the volume: AI makes a plausible vulnerability report quick to write and slow for a maintainer to disprove.