All stories
AI

Google Halts Open Source Bug Bounty Program Amid AI-Generated Report Deluge

Google has temporarily paused its Open Source Software Vulnerability Reward Program (OSS VRP) effective October 1, 2026, due to an "overwhelming surge of invalid, AI-generated reports," signaling a critical industry-wide challenge where AI's acceleration of discovery now outpaces human verification, threatening the integrity of cybersecurity defenses.

By TECH NEWS Editorial·Source:TechCrunch·4 min read·4h ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Google Halts Open Source Bug Bounty Program Amid AI-Generated Report Deluge

Google has temporarily halted product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP), effective October 1, 2026, due to an overwhelming surge of invalid, AI-generated reports. This operational freeze, announced via a post on X, marks a critical juncture for the cybersecurity industry, highlighting the double-edged sword of artificial intelligence in vulnerability discovery. Google aims to restructure its submission framework, with an official progress update expected in the first quarter of 2027, while supply chain disclosures under the OSS VRP and certain Google Cloud VRP product vulnerability reports remain active.

The implications of Google's decision reverberate throughout the digital ecosystem, impacting both the integrity of open-source software and the very mechanisms designed to secure it. For users, this "AI slop" — low-quality submissions that exhaust resources without identifying genuine threats — could lead to a degradation of the overall security posture of widely used open-source components. When maintainers and security engineers are buried under thousands of poorly written, often hallucinatory reports, their capacity to identify and remediate real, critical vulnerabilities is severely hampered. This creates a dangerous bottleneck where discovery, now accelerated by AI, far outpaces the human ability to verify and patch. The risk is that legitimate, high-impact flaws remain unaddressed longer, leaving crucial software exposed to malicious actors who are also increasingly leveraging AI for exploitation and augmented operations.

This isn't an isolated incident; similar scenarios are playing out across the industry. Linux maintainers, for instance, reported being "completely overwhelmed" by bogus Common Vulnerabilities and Exposures (CVE) filings, with AI-powered hunters driving recorded vulnerabilities to a record high of 2,000 per release, forcing the project to drop support for older network drivers. Chipmaker Intel also recently froze its bug bounty program, which offered payouts reaching $100,000 per flaw, with experts suspecting AI-generated reports as the reason. Other platforms like HackerOne's Internet Bug Bounty program and Curl's bug bounty have paused or ended their initiatives due to similar issues, with Turso explicitly "retiring" its program in May 2026 due to the "semi-infinite pace" of AI slop. GitHub, another major player, restructured its bug bounty into a two-tier system in July 2026, introducing a lower-paying public program and a higher-paying invitation-only tier, directly in response to a growing backlog of low-effort and AI-generated reports. These collective actions underscore a systemic challenge, where the traditional bug bounty model, designed for a world where discovery was the bottleneck, is now struggling with verification, prioritization, and patching.

Historically, bug bounty programs have evolved significantly since their inception, transforming from informal disclosures into a multi-billion-dollar industry adopted by tech giants, startups, and governments. They were built on the premise of leveraging a global community of ethical hackers, providing incentives for painstaking, manual work that required skill and human ingenuity. While AI was anticipated to assist researchers with automated scans and vulnerability searches, the current reality sees it generating an unprecedented volume of low-quality output, often with thin evidence and templated language, creating an immense triage burden. The focus has shifted from AI as an assistant to AI as a source of overwhelming noise, challenging the fundamental "signal versus noise" dynamic that makes these programs effective.

Looking ahead, Google's commitment to an update in Q1 2027 suggests a fundamental re-evaluation of how vulnerability reports are handled in the age of AI. The future of bug bounties will likely necessitate advanced AI/ML filters for submissions, capable of deduplication, clustering, and automated context enrichment, to help human teams focus on judgment and decision-making. Strict verification mechanisms, such as mandatory proof-of-concept execution or researcher reputation thresholds, are expected to become standard. This could lead to a polarization of the market, where "augmented hunters" using AI as a tool for complex, sophisticated bugs thrive, while those relying solely on AI to generate superficial reports find diminishing returns. Industry-wide collaboration on standards for AI-generated reports and perhaps even a shift towards rewarding researchers for *fixes* rather than just discoveries could emerge. The core value of bug bounties — anchored to real-world exploitation and risk — will persist, but the emphasis will be on human ingenuity to validate impact and navigate the complexities that AI alone cannot. Google, having recently restricted public access to its powerful Gemini 4 Argon model to vetted cybersecurity experts due to misuse concerns, understands the dual nature of AI's capabilities. The company itself leverages AI agents like Big Sleep to find vulnerabilities and Gemini's reasoning via CodeMender to fix them, demonstrating a commitment to using AI as a powerful tool for defenders. The challenge now is to apply that same innovative spirit to filter the noise and preserve the invaluable human element in the critical task of securing open-source software.

Sources