Google pauses open-source bug bounty program over AI-generated submissions
TECH

Google pauses open-source bug bounty program over AI-generated submissions

27+
Signals

Strategic Overview

  • 01.
    Google temporarily stopped accepting new OSS VRP product vulnerability submissions effective October 1, 2026, citing a significant rise in automated submissions, the vast majority of which are not valid.
  • 02.
    The freeze covers Google-maintained projects including Go, Angular, Bazel, Protocol Buffers, and Fuchsia, but does not affect OSS VRP supply-chain reports or any previously submitted/outstanding reports.
  • 03.
    Google is directing researchers to its other active tracks during the pause, including the Patch Rewards Program (up to $15,000 for verified fixes) and Cloud VRP, and has committed to an update in Q1 2027.
  • 04.
    Google's VRP has paid out more than $81.6 million since 2010, including $17.1 million to over 700 researchers in 2025 alone, a 40% increase over 2024.

Deep Analysis

The Hallucination Problem: Why AI Slop Fools Human Reviewers

Google's own framing undercuts the easy narrative that AI-written reports are the problem by definition. An analysis of the pause argues the issue isn't that generative AI wrote the submissions - it's that so many of them are wrong. Poorly written, incomplete, and hallucinated reports are not always immediately recognizable as such [1], which is exactly what makes them expensive: a fabricated exploit path or a claim about a function that isn't reachable the way the report describes still has to be manually traced through source code before a reviewer can rule it out. Google confirmed the trigger was blunt volume, not just bad luck - a significant rise in automated submissions, the vast majority of which are not valid [2]. The two problems compound: more submissions mean more hours spent disproving plausible-sounding fictions, and that reviewer time comes directly out of time that would otherwise go toward real vulnerabilities in projects like Go, Angular, Bazel, and Fuchsia. Google's own public framing matched that math rather than panic - the announcement read as a routine administrative notice rather than a crisis statement - but outside commentary and press pickup read it more dramatically, framing it as evidence that AI slop is now breaking bug bounty programs outright, and drawing the most debate of any single post on the story.

Google Isn't the First - curl and HackerOne Already Broke Under the Same Load

Google is acting last among major programs forced into the same corner, not first. curl's maintainer ended a six-year-old HackerOne bounty on January 31, 2026 after estimating that roughly 20% of its submissions were AI slop, while only about 5% of the year's reports were genuine vulnerabilities - including a stretch where seven invalid reports landed within sixteen hours [3]. Two months later, HackerOne's own Internet Bug Bounty, which had funded open-source fixes since 2013, stopped taking new submissions entirely [3]. Google's OSS VRP, covering Go, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies [2], is simply the largest and most visible name yet to hit the same wall, which suggests the triage economics are breaking industry-wide rather than reflecting a Google-specific management failure. That framing is already bleeding into mainstream tech commentary, where 'is bug bounty dead' has become its own recurring question independent of any single company's incident.

The Money at Stake: Why Google Paused Instead of Walked Away

The reason these programs keep getting flooded is a cost asymmetry that generative AI makes worse every month: producing a bug report now costs the submitter almost nothing, while validating one still requires a human engineer's time. The money at stake explains why Google chose a pause rather than letting the noise pile up indefinitely - its VRP has paid out more than $81.6 million since 2010 [2], and 2025 alone saw $17.1 million distributed to over 700 researchers, a 40% jump from 2024 [4]. Individual OSS VRP rewards range from $100 to $31,337, with a separate Patch Rewards track paying up to $15,000 for verified fixes [2]. That is a program worth protecting rather than abandoning outright, which is likely why Google froze only the product-vulnerability intake instead of shutting OSS VRP down the way curl walked away from HackerOne altogether.

A Narrow Freeze, Not a Shutdown - and an Open Question for Q1 2027

Google drew a narrower line than it might appear at first glance. The freeze applies only to new OSS VRP product vulnerability submissions - supply-chain reports and anything already in the queue keep moving [1]- and Google is actively steering researchers toward its Patch Rewards Program and Cloud VRP in the meantime [5]. The company has committed to an update in Q1 2027 [2], which leaves the real question unresolved. Security researchers discussing the pause online are already betting on an answer: that bounty programs respond by narrowing scope and gating access by reputation rather than staying fully open, since report volume, not report quality, is what now breaks a triage team's budget. Whether Google's Q1 2027 update confirms or avoids that path is the thing worth watching.

Historical Context

2022-08
Google originally announced the OSS VRP on the Google Security Blog as part of its broader open-source security push.
2025-07
curl's maintainer estimated that about 20% of all bug bounty submissions were AI slop, with only around 5% of the year's submissions being genuine vulnerabilities.
2026-01-31
curl ended its six-year HackerOne bug bounty program after AI-generated reports overwhelmed its security team, including seven invalid reports within a single 16-hour stretch.
2026-03
Google published its VRP 2025 Year in Review, reporting total 2025 payouts of $17.1 million to over 700 researchers, a 40% increase over 2024.
2026-03-27
HackerOne's Internet Bug Bounty, which had funded open-source fixes since 2013, stopped accepting new submissions amid the same AI-generated report pressure.
2026-10-01
Google froze new OSS VRP product vulnerability submissions, citing a significant rise in automated, mostly invalid submissions.

Power Map

Key Players
Subject

Google pauses open-source bug bounty program over AI-generated submissions

GO

Google VRP / Google Bug Hunters team

Program operator that made and announced the pause decision via its official channel and @GoogleVRP account on October 1, 2026.

OP

Open-source maintainers (Go, Angular, Fuchsia, Protocol Buffers, Bazel)

Downstream reviewers who bore the triage burden of invalid AI-generated reports and are the direct beneficiaries of the pause.

CU

curl project

Set the precedent by ending its six-year HackerOne bug bounty on January 31, 2026 after being overwhelmed by AI-slop reports.

HA

HackerOne / Internet Bug Bounty

Third-party platform whose Internet Bug Bounty, funding open-source fixes since 2013, stopped accepting new submissions on March 27, 2026 under the same pressure.

AI

AI-assisted bug-hunting submitters

Source of the submission surge, using AI tools to generate vulnerability reports at scale, most of which are invalid or hallucinated.

Fact Check

5 cited
  1. [1] Google had to break its OSS VRP to escape a tidal wave of AI-generated bug reports
  2. [2] Google halts open source bug bounty program amid AI spam surge
  3. [3] curl ending bug bounty program after flood of AI slop reports
  4. [4] Google VRP 2025 Year in Review
  5. [5] Google pauses open source bug bounty program

Source Articles

Top 5

THE SIGNAL.

Analysts

“Argues the problem is not that AI generated the reports, but that the reports are low-quality and hallucinated, and that this burden is affecting the entire security-research industry, not just Google.”

ITdaily security desk (Michaël Aussems)
Author, ITdaily
The Crowd

“PSA for open-source bug hunters. We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs”

@@GoogleVRP335

“Google has frozen its open source bug bounty program after a significant rise in AI submissions, according to TechCrunch. The report says AI slop may be overwhelming bug bounty programs. #Applitank #Google #BugBounty #OpenSource”

@@applitank202

“AI slop seems to be overwhelming bug bounty programs.”

@@TechCrunch67

“Google suspended their OSS VRP”

@u/CellAccomplished114912
Broadcast
Is Bug Bounty Really Dead?

Is Bug Bounty Really Dead?

Is Bug Bounty Dead? (Ep. 173)

Is Bug Bounty Dead? (Ep. 173)

Bug Bounty in 2026 is Smashed | AI Slop vs Real Hackers (SftSec Tim Podcast)

Bug Bounty in 2026 is Smashed | AI Slop vs Real Hackers (SftSec Tim Podcast)