Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has temporarily halted product vulnerability submissions for its open-source software bug bounty program, citing a massive surge in automated and invalid AI-driven reports. The suspension, which began on October 1, blocks security researchers from submitting code flaws for projects like Go, Angular, and Protocol Buffers to receive financial rewards. Maintainers faced an overwhelming flood of hallucinations and invalid automated claims. Google stated the pause will last until 2027, though reports concerning supply chain compromises continue to be accepted.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Google paused its open source bug bounty program due to a significant rise in automated submissions, the vast majority of which are not valid.
- ✓ Product flaw submissions are halted until 2027.
- ✓ Projects affected by the halt include Go, Angular, and Protocol Buffers.
- ✓ Reports about supply chain compromises are still accepted, and reports filed before October 1 are unaffected.
What changed
Google implemented a temporary freeze on product vulnerability submissions for its open source bug bounty program starting October 1.
Live updates
-
Google Freezes Open Source Bug Bounty Due to AI Submissions
Google has temporarily halted product vulnerability submissions for its open-source software bug bounty program, citing a massive surge in automated and invalid AI-driven reports. The suspension, which began on October 1, blocks security researchers from submitting code flaws for projects like Go, Angular, and Protocol Buffers to receive financial rewards. Maintainers faced an overwhelming flood of hallucinations and invalid automated claims. Google stated the pause will last until 2027, though reports concerning supply chain compromises continue to be accepted.
Why it matters
Open-source security programs rely heavily on external researchers to discover and report genuine product flaws. An influx of automated, low-quality submissions can overwhelm human maintainers, delaying patches for real vulnerabilities. The decision highlights growing industry challenges regarding the abuse of generative artificial intelligence tools in cybersecurity reporting.
What is confirmed
- Google paused its open source bug bounty program due to a significant rise in automated submissions, the vast majority of which are not valid.
- Product flaw submissions are halted until 2027.
- Projects affected by the halt include Go, Angular, and Protocol Buffers.
- Reports about supply chain compromises are still accepted, and reports filed before October 1 are unaffected.
Still unconfirmed
- The massive influx of invalid bug reports was specifically produced using AI tools, according to tech media interpretations, though Google's official post did not explicitly state whether the automated submissions were generated by AI.
What to watch next
- Any official announcement from Google regarding changes to submission verification processes before 2027
- Whether other major technology companies follow Google's lead in pausing open-source bug bounty programs due to automated traffic
confidence 95%Sources used for this update (12)
- TechCrunch — Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
- Tom's Hardware — Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
- IT Pro — ‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissions
- infosecurity-magazine.com — Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
- FOX Sports Radio — Google Shuts Down Bug Bounty Program Due To Bots
- thehackernews.com — Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
- tech.yahoo.com — Google froze its open source bug bounty program due to a ...
- techcrunch.com — Google froze its open source bug bounty program due to a ...
- www.infosecurity-magazine.com — Google Suspends Open-Source Bug Bounty Due to AI ...
- www.malwarebytes.com — Google pauses open source bug bounty program after rise in AI ...
- tech.yahoo.com — Google freezes open-source bug bounty program amid flood of ...
- www.techradar.com — Google benches open source bug bounty program following ...
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community