Google pauses open source bug bounty program over AI spam
Google plans to provide an update on the pause in the first quarter of 2027.
In response to a "significant rise" in AI-generated submissions, Google has halted its open source bug bounty program, set to remain on pause until next year. The move comes after cybersecurity experts had previously cautioned about potential risks posed by AI to bug bounty initiatives. This issue now appears to be affecting Google's Open Source Software Vulnerability Rewards Program, where researchers are compensated for identifying vulnerabilities in the company's open source software.
Google announced the suspension of the bug bounty program on October 1 via posts on X and its program website, with a commitment to provide an update in the first quarter of 2027. According to Tom's Hardware, the overwhelming number of reports received by Google engineers and open source maintainers were found to be invalid or contained hallucinations caused by AI. The company explained that this pause is a direct result of the surge in automated submissions, the majority of which were found to be invalid.
During this period of pause, Google has urged participants to explore its other bug bounty programs while they address the issue.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.