Blaming a significant and unsustainable rise in low-quality automated submissions, Google has officially paused its prominent open-source bug bounty program until next year. The decision highlights a growing crisis within the cybersecurity community, where the widespread availability of generative artificial intelligence tools is creating unprecedented operational hurdles for technology companies and open-source maintainers alike.
The suspension impacts Google’s Open Source Software Vulnerability Rewards Program, a specialized initiative designed to incentivize independent cybersecurity researchers and ethical hackers to discover, report, and help remediate security flaws across the company’s vast portfolio of open-source projects. For years, these types of bug bounty programs have served as a critical pillar of modern software security, leveraging crowdsourced talent to identify vulnerabilities that internal teams might otherwise miss.
However, the rapid evolution and democratization of artificial intelligence have fundamentally shifted the dynamics of vulnerability reporting. Last year, cybersecurity experts began sounding loud alarms that the proliferation of low-effort, AI-generated content—often colloquially referred to as "AI slop"—posed an escalating and severe risk to the integrity of vulnerability disclosure programs. Industry analysts warned that bad actors and opportunistic individuals were increasingly utilizing automated scripts and generative AI models to flood bug bounty platforms with speculative, inaccurate, or entirely fabricated security reports in the hope of securing financial payouts.
It appears that exact threat has now overwhelmed Google’s engineering teams. In official statements shared across social media on X and updated directly on the program’s official website, Google announced that the open-source bug bounty initiative was paused as of October 1. The company has promised to provide a formal update regarding the future of the program sometime in the first quarter of 2027.
According to reports from industry tracking, the sheer volume of incoming material severely strained internal resources. Google engineers, alongside independent open-source maintainers who volunteer their time to protect critical software libraries and frameworks, found themselves drowning in a massive backlog of reports that were either entirely invalid or filled with convincing yet completely false AI-generated hallucinations. These hallucinations often describe complex software vulnerabilities that do not actually exist in the codebase, requiring hours of manual, tedious verification by human experts just to separate legitimate security threats from automated noise.
In its public communication, the technology giant addressed the root cause of the operational shutdown directly, noting that the pause is due to a significant rise in automated submissions, the vast majority of which are not valid. The influx of automated noise has effectively crippled the efficiency of the review process, making it impossible for security teams to manage genuine security submissions in a timely and effective manner.
The temporary closure of the open-source vulnerability rewards program marks a notable setback for collaborative software security, underscoring the unintended negative consequences of generative AI technology on traditional industry practices. While artificial intelligence has undoubtedly provided powerful new capabilities for defensive security operations and code analysis, it has simultaneously lowered the barrier of entry for generating low-quality noise at scale.
Despite the suspension of this specific initiative, Google continues to maintain its various other vulnerability reward programs covering different sectors of its ecosystem. In the meantime, security researchers and ethical hackers interested in contributing to the company’s security posture are being encouraged by Google to redirect their efforts toward these alternative channels while the company evaluates how to better filter and manage submissions moving forward.
