2026-10-05 11:41 UTC
DANGMUAAI & Developer Tools, Decoded
BackIndustry

Google Pauses Open Source Bug Bounty Over AI Slop Reports

Google froze its Open Source Vulnerability Rewards Program on October 1, citing a significant rise in automated submissions. An update is due in Q1 2027.

DangMua EditorialOct 05, 20263 min read
Google Pauses Open Source Bug Bounty Over AI Slop Reports

Google paused its Open Source Software Vulnerability Rewards Program on October 1, blaming a "significant rise" in automated submissions. The company says it will give "an update" in the first quarter of 2027 — no earlier resumption date.

What Google said

The statement, posted on X and on the program website, is short and names the cause directly: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said. The program paid researchers for finding vulnerabilities in Google's own open source software. It is suspended with no fixed end date, and participants are pointed at Google's other bug bounty programs in the meantime.

On the operational damage, TechCrunch cites Tom's Hardware reporting that Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. That detail is secondhand and worth treating as reporting rather than a Google disclosure — Google's own wording stops at "not valid."

This was forecast a year ago

TechCrunch reported last year that cybersecurity experts were warning AI slop posed a serious risk to bug bounty programs. The mechanism they described is the one that landed: automated tools generate plausible-looking but false vulnerability reports faster than humans can verify them. The warning was general; Google's VRP is where it has now produced a shutdown.

The asymmetry that broke the queue

Strip out the security specifics and the failure is arithmetic. Submission cost falls toward zero when a model writes the submission. Review cost does not fall at all, because a human still has to judge whether a claimed vulnerability is real. Volume alone then breaks a process that worked fine at smaller scale — no individual bad actor required, and no single report that is obviously fake.

That shape is not unique to security research. Any open intake channel has it: support queues, sales inquiry forms, vendor onboarding, RFP submissions, inbound hiring. All of them assume submission takes effort, and that assumption is what stopped being true.

Why most teams can't copy Google's fix

Google closed the channel. For a bug bounty that is tolerable, because the program is a supplement to internal security work rather than the source of it. Most companies don't have that option — the inbox in question is how deals, support requests and hires arrive in the first place. Shutting it costs more than the slop does.

The move available to everyone else is validation placed before the human step rather than after it: automated checks for duplication, internal consistency, specificity and plausibility that flag or deprioritize weak submissions before a reviewer spends time on them. Screening content is a narrower and more defensible use of a model than generating it, and it is the only layer that scales with submission volume instead of with headcount.

Two design notes for anyone building that layer. Deprioritize rather than reject, because a false negative on a real vulnerability report is far more expensive than a few minutes wasted on a false positive. And log what the filter catches — the queue composition is the early warning that tells you whether you are weeks or months from Google's position.

What to watch

The first quarter of 2027 update is the signal to track. If the program returns with structural changes — reputation gating, paid submission deposits, mandatory proof-of-concept — those become the template other programs copy. If it returns unchanged, or doesn't return, the read is that nobody has a working filter yet, and every open intake channel in the industry is running on borrowed time.

More from DangMua