AI

Google Pauses Open Source Bug Bounty Program Over AI Spam

The tech giant halted its vulnerability reward scheme after automated, AI-generated reports overwhelmed engineers and slowed triage efforts.

  • Google has officially suspended its Open Source Software Vulnerability Rewards Program, citing a massive surge in low-quality submissions generated by artificial intelligence.
  • The decision follows mounting pressure on Google engineers and open…
  • The Scale Report understands that the incident underscores a broader tension within the cybersecurity industry.
Google Pauses Open Source Bug Bounty Program Over AI SpamThe Scale Report

Google has officially suspended its Open Source Software Vulnerability Rewards Program, citing a massive surge in low-quality submissions generated by artificial intelligence. According to TechCrunch, the company implemented the freeze on October 1 and does not expect to provide further updates until the first quarter of 2027.

Impact of Automated Vulnerability Reports

The decision follows mounting pressure on Google engineers and open source maintainers who have struggled to manage an influx of invalid findings. Many of these submissions, as reported by Tom’s Hardware, consist of hallucinations or errors produced by automated tools, forcing staff to sift through noise to find legitimate security threats.

The Scale Report understands that the incident underscores a broader tension within the cybersecurity industry. As generative AI becomes more accessible, the barrier to entry for participation in crowdsourced bug bounty programs has effectively vanished, leading to a deluge of bad data that threatens to undermine the viability of incentive-based security research.

While this specific open source channel remains closed, the company has encouraged security researchers to redirect their efforts toward other active programs within its ecosystem. Industry observers note that the move highlights the growing difficulty of verifying machine-generated research, a trend that may force other tech giants to implement stricter filtering mechanisms for their own security programs in the coming months.

Reporting based on coverage from AI News & Artificial Intelligence | TechCrunch.

The daily brief

The biggest stories in AI, venture, sports business and culture - once a day.

One short email from The Scale Report. No spam, unsubscribe any time.

Read next