Google halted its open source bug bounty program on October 1. The company blamed a significant increase in automated submissions. Most of these reports proved invalid or contained AI hallucinations.
Cybersecurity experts previously warned that artificial intelligence tools posed serious risks to bug bounty programs. These automated systems generated low quality reports that flooded triage teams. Google ran the Open Source Software Vulnerability Rewards Program to pay researchers who found genuine security flaws. Engineers and open source maintainers struggled to process the overwhelming volume of incoming data.
Automated reports overwhelmed the system
The vast majority of the recent submissions lacked validity. Google announced the pause through posts on X and on the official program website. Participants cannot submit new reports for open source software until the freeze lifts.
Google directed researchers toward its other active bug bounty programs in the interim. The influx of automated content created unmanageable workloads for project maintainers. The tech giant chose to freeze operations entirely to address the issue.
Google plans an update in 2027
Google promised to provide a status update on the bug bounty program during the first quarter of 2027. The temporary halt will last until next year while the team evaluates the situation.



