Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Google Paused Its Open Source Bug Bounty Program Over ‘A Significant Rise’ in Automated Submissions

Google froze its open source bug bounty program due to a 'significant rise' in AI submissions, overwhelming engineers with invalid reports.

By mitch·6 min read
A hand pauses a control panel switch amid a glowing server room filled with streaming binary code.

Google has paused its open source bug bounty program indefinitely, and the reason is not what you might expect. The program, which rewards researchers for finding vulnerabilities in the company’s open source software, was frozen as of October 1. Google said the move was due to a “significant rise” in automated submissions — the vast majority of which are not valid.

The company posted the news on X and on the program website. It promised to provide “an update” in the first quarter of 2027. In the meantime, participants are encouraged to consider Google’s other bug bounty programs.

Pause Details and the Company’s Statement

The move is notable because it was widely predicted. Last year, TechCrunch reported that cybersecurity experts were warning of the risk that AI slop posed to bug bounty programs. That warning now appears to have come true, at least for Google.

Advertisement

The company’s statement was direct. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said.

The details are thin so far. Google did not say how many invalid submissions it received, or how they were identified as invalid. It did not say whether any valid reports were lost in the flood. It did not say whether the pause will change how the program operates when it resumes.

What Google did say is that the problem was not human. The submissions came from machines, and most of them were wrong.

How the Program Worked Before the Pause

Before the pause, the Open Source Software Vulnerability Rewards Program rewarded researchers for finding vulnerabilities in Google’s open source software. The program was designed to encourage security researchers to look at the company’s code and report problems before they could be exploited.

The program worked by offering cash rewards for valid reports. Researchers submitted a report, Google reviewed it, and if the report was confirmed, the researcher got paid.

The program was part of a broader effort by Google to secure its open source projects. Open source software is code that is freely available for anyone to use, study, and modify. It is a cornerstone of the modern software ecosystem, and it carries risks because anyone can look at the code.

Google’s program was meant to turn those risks into rewards.

Why the Pause Was Necessary

The pause is a direct consequence of what happened to the program. Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. The company said that the vast majority of these submissions were automated.

The term “hallucinations” is telling. In the context of AI, a hallucination is a piece of output that is generated by a model but is not based on real data. An AI might generate a report that looks real but is entirely made up.

Google engineers now have to sift through a stream of submissions to separate the real reports from the machine-generated noise. The company described the situation in blunt terms.

What the company did say is that the volume was so large that the program became unmanageable.

The Warning From Last Year

The irony is that experts were raising concerns about this problem last year. TechCrunch reported that cybersecurity experts were warning of AI slop — the risk that automated systems could flood bug bounty programs with noise.

The warning was specific. It was not a prediction that AI submissions would one day overwhelm a program. It was a warning that the risk was real.

Now that risk has materialized. Google is the company facing it.

What Happens Next

The program is paused until the first quarter of 2027. That is a long time to wait for a fix. The company has not said what the fix will look like. It has not said whether the program will return with the same rules, with new rules, or not at all.

The company’s statement suggests that the pause is temporary. The promise to provide “an update” in the first quarter of 2027 implies that the program will resume at some point.

Google has not said whether it will change the submission process. It has not said whether it will require researchers to prove they are human before submitting. It has not said whether it will limit the number of submissions or the rate at which they can be made. It has not said whether it will introduce a screening step that catches invalid reports before they reach engineers.

The company has not said whether the pause will affect the overall volume of reports it receives. It has not said whether the pause will change the mix of reports it receives. It has not said whether the pause will affect the quality of reports it receives.

The Encouragement to Try Other Programs

While the program is paused, participants are encouraged to consider Google’s other bug bounty programs. Google runs several such programs, each focused on a different area of its operations.

The encouragement is a practical one. Researchers who were planning to submit to the open source program now have other options. Google is not abandoning its bug bounty efforts entirely — it is simply redirecting them.

The encouragement also carries a message. Google is telling the security community that it is still interested in working with researchers, even if the open source program is closed for now.

The Hard Numbers

  • Pause begins: October 1
  • Program resumed: Not yet announced
  • Next update promised: First quarter of 2027
  • Reason for pause: “A significant rise in automated submissions, the vast majority of which are not valid”
  • Statement posted: X and the program website

What This Means for Researchers

The pause changes the calculus for security researchers. If you were planning to submit a report to the open source program, you now have to consider whether the effort is worth it.

The pause also raises a broader question about the future of bug bounty programs. If automated submissions are flooding one program, they could flood others.

The pause is also a warning to the security community. If you are building an AI system that generates reports, you should expect that your submissions will be treated with skepticism. The flood of noise has consequences, and the companies that run bug bounty programs are not obligated to deal with it.

The pause is a reminder that the tools that make our lives easier — like AI — also make our lives harder in unexpected ways.

Google’s move is a blunt instrument. It is also a clear signal. The company is saying that it cannot manage the volume of submissions it is receiving, and it is willing to shut down a program rather than let it become a noise machine.

The pause will last until the first quarter of 2027. After that, the company will provide an update. Until then, researchers are encouraged to look elsewhere.

The program is paused. The question is what the program will be when it returns.

Source material: “Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions,” TechCrunch.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.