Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 3 min read

Google pauses its open-source bug bounty over AI reports

Google stopped accepting new vulnerability reports for its Open Source Software Vulnerability Reward Program, or OSS VRP, on October 1, 2026. "This pause is due to a significant rise in automated submissions, the vast ma

Google stopped accepting new vulnerability reports for its Open Source Software Vulnerability Reward Program, or OSS VRP, on October 1, 2026. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," Google said, as quoted by TechCrunch. The program pays outside researchers who find security bugs in Google's open-source projects. The freeze closes one of the main paid routes for reporting flaws in tools such as Go and Angular.

What Google paused and what stays open

A bug bounty pays people who find and report security flaws. Google's notice reads: "We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports." BleepingComputer and Help Net Security both quote it.

Supply chain reports cover the systems that build and ship the code, rather than bugs in the code itself. Here is where each route stands, according to BleepingComputer:

Route Status
New OSS VRP product vulnerability reports Paused since October 1
OSS VRP supply chain reports Still accepted
Reports already submitted Still handled
Google Patch Rewards Program Open, up to $15,000 for high-impact fixes
Google Cloud VRP Open

What the program covered

Google launched the OSS VRP in August 2022, with rewards from $100 to $31,337, BleepingComputer reports. It covers Go, Angular, Bazel, Protocol Buffers, Fuchsia and critical third-party code those projects depend on. Bazel is a build tool, Protocol Buffers is a data format for sending structured data between programs, and Fuchsia is an operating system.

Google's bounty spending has been climbing. It paid a record $17.1 million to more than 700 security researchers in 2025, according to BleepingComputer. That was a 40% increase on the $12 million it paid in 2024.

Why AI reports broke the system

An AI chatbot can write a bug report that looks convincing in seconds. Google says the vast majority of the automated reports it received were not valid. Each one still needs a person to read it and try to reproduce the bug.

TechCrunch notes that it warned in July 2025 that this kind of "AI slop" posed a serious risk to bug bounty programs. It has promised a new plan. Help Net Security quotes the company's pledge: "We will continue to reformat and work on this aspect of the OSS VRP." Google added that it will "commit to giving an update in Q1 2027."

Google is not the first to pull back

Two other well-known programs changed course this year, BleepingComputer reports:

Program Change
curl Ended its HackerOne bug bounty in January 2026 after a flood of AI-written reports
Intel Removed financial rewards in mid-September 2026, without explaining why

AI tools can also find real flaws when a person checks the results. A 16-year-old's home-built AI tool helped expose a Microsoft analytics flaw, which earned him a $5,000 bounty.

What this means for developers

If you found a real bug in Go, Angular or another covered project, still report it. The paid route is closed, but the projects' normal security contacts still need to hear about flaws. If you can also write the fix, the Patch Rewards Program still pays up to $15,000.

If you hunt bugs with AI tools, check every finding by hand first. Reproduce it, confirm the impact, and cut anything you cannot prove. Unverified reports are the reason this program closed.

If you maintain an open-source project, expect the same flood to reach your security inbox. Ask for a working proof of concept and exact steps to reproduce before anyone spends time on triage. A short report template filters out much of the noise. Decide now whether your project pays for reports at all.

Watch for Google's update in the first quarter of 2027. The rules it picks will show how large programs plan to live with AI-written reports.

This article was first published on Tech AI Wire.

Also available in

Deutsch Β· ζ—₯本θͺž Β· FranΓ§ais Β· EspaΓ±ol Β· PortuguΓͺs

Related on Tech AI Wire

Sources

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.