Google Pauses Open Source Bug Bounty Program Over AI Spam
The tech giant halted its vulnerability reward scheme after automated, AI-generated reports overwhelmed engineers and slowed triage efforts.
Key highlights · 3 min read
- Google has officially suspended its Open Source Software Vulnerability Rewards Program, citing a massive surge in low-quality submissions generated by artificial intelligence.
- The decision follows mounting pressure on Google engineers and open…
- The Scale Report understands that the incident underscores a broader tension within the cybersecurity industry.
The Scale ReportGoogle has officially suspended its Open Source Software Vulnerability Rewards Program, citing a massive surge in low-quality submissions generated by artificial intelligence. According to TechCrunch, the company implemented the freeze on October 1 and does not expect to provide further updates until the first quarter of 2027.
Impact of Automated Vulnerability Reports
The decision follows mounting pressure on Google engineers and open source maintainers who have struggled to manage an influx of invalid findings. Many of these submissions, as reported by Tom’s Hardware, consist of hallucinations or errors produced by automated tools, forcing staff to sift through noise to find legitimate security threats.
The Scale Report understands that the incident underscores a broader tension within the cybersecurity industry. As generative AI becomes more accessible, the barrier to entry for participation in crowdsourced bug bounty programs has effectively vanished, leading to a deluge of bad data that threatens to undermine the viability of incentive-based security research.
While this specific open source channel remains closed, the company has encouraged security researchers to redirect their efforts toward other active programs within its ecosystem. Industry observers note that the move highlights the growing difficulty of verifying machine-generated research, a trend that may force other tech giants to implement stricter filtering mechanisms for their own security programs in the coming months.
Reporting based on coverage from AI News & Artificial Intelligence | TechCrunch.




