Updated
Updated · TechCrunch · Oct 4
Google Pauses Open Source Bug Bounty Until 2027 as AI Reports Overwhelm Reviewers
Updated
Updated · TechCrunch · Oct 4

Google Pauses Open Source Bug Bounty Until 2027 as AI Reports Overwhelm Reviewers

3 articles · Updated · TechCrunch · Oct 4

Summary

  • Google halted its Open Source Software Vulnerability Rewards Program on Oct. 1 and said it will issue an update in the first quarter of 2027.
  • A significant rise in automated AI submissions drove the pause, with Google saying the vast majority were invalid and many reports contained hallucinations.
  • Engineers and open source maintainers were being overwhelmed by low-quality vulnerability claims, undercutting the program that pays researchers to find flaws in Google's open source software.
  • Participants are being redirected to Google's other bug bounty programs, as concerns grow that AI-generated 'slop' is straining vulnerability disclosure systems more broadly.

Insights

As AI spam forces Google to halt open-source rewards, what happens to the legitimate hackers whose real warnings are now buried in noise?
Can the cybersecurity industry survive the flood of AI slop, or is the traditional bug bounty model permanently broken by automated hallucinations?