
Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a “significant rise” in automated AI-generated submissions that overwhelmed engineers with invalid or hallucinated vulnerability reports. The program, which rewards researchers for finding genuine security flaws in Google’s open-source software, will remain suspended until at least the first quarter of 2027.
The company explained that the vast majority of recent submissions were not valid — many were generated by AI tools that produced plausible-sounding but ultimately incorrect vulnerability assessments. Engineers and open-source maintainers found themselves spending significant time reviewing reports that contained fabricated evidence or described nonexistent flaws. This validates earlier warnings from cybersecurity experts who predicted that AI-generated “slop” would undermine the effectiveness of bug bounty programs.
Google posted the announcement on X and the program’s website, encouraging participants to consider the company’s other bug bounty programs in the meantime. The freeze highlights a growing tension in the cybersecurity world: AI tools can accelerate vulnerability discovery, but they can also flood security teams with low-quality output, creating noise that makes it harder to identify genuine threats. As AI coding tools become more deeply embedded in software development workflows, the volume of AI-assisted vulnerability reports — both valid and invalid — is expected to increase.