{
  "id": 12000080,
  "title": "Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions",
  "url": "https://urgent.news/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-04T20:31:07.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/"
  },
  "original_language": "en",
  "account": "In response to a \"significant rise\" in AI-generated submissions, Google has halted its open source bug bounty program, set to remain on pause until next year. The move comes after cybersecurity experts had previously cautioned about potential risks posed by AI to bug bounty initiatives. This issue now appears to be affecting Google's Open Source Software Vulnerability Rewards Program, where researchers are compensated for identifying vulnerabilities in the company's open source software.\n\nGoogle announced the suspension of the bug bounty program on October 1 via posts on X and its program website, with a commitment to provide an update in the first quarter of 2027. According to Tom's Hardware, the overwhelming number of reports received by Google engineers and open source maintainers were found to be invalid or contained hallucinations caused by AI. The company explained that this pause is a direct result of the surge in automated submissions, the majority of which were found to be invalid.\n\nDuring this period of pause, Google has urged participants to explore its other bug bounty programs while they address the issue.",
  "summary": "AI slop seems to be overwhelming bug bounty programs.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}