Google halts open-source bug bounty program amid AI spam surge

A major open-source bug bounty program has been temporarily suspended due to a flood of low-quality reports generated by artificial intelligence (AI) tools. Google’s Open Source Software Vulnerability Rewards Program (OSS VRP), which rewards security researchers for identifying vulnerabilities in open-source projects maintained by the tech giant, is currently not accepting new submissions.

The pause affects over 60 open-source projects, including Golang, Angular, and Fuchsia, among others. The program, launched in August 2022, aimed to incentivize responsible disclosure of critical security flaws that could impact the software supply chain. However, Google has been overwhelmed by an influx of automated submissions from AI tools, with most reports deemed invalid.

According to Google, researchers can still submit security patches for open-source software through the company’s Patch Rewards Program (PRP), which offers bounties up to $15,000 for high-impact fixes. Additionally, vulnerability reports affecting Google Cloud open-source repositories can be submitted through the company’s Cloud VRP. While this may seem like a convenient solution, it’s essential to note that these programs have different reward structures and eligibility criteria.

The temporary suspension of OSS VRP highlights the growing challenges faced by bug bounty programs in today’s AI-driven landscape. With more developers turning to AI tools for vulnerability discovery, the quality of submissions has significantly decreased. In January, the maintainer of the curl command-line utility ended its HackerOne security bug bounty program due to a similar issue.

Google is taking steps to address this problem and will reformat the OSS VRP in early 2027. However, this may not be the only casualty of AI-generated reports. Microsoft warned earlier this year that AI tools would lead to an increase in vulnerability discovery, which could put operational demands on bug bounty programs. In fact, last month, Microsoft released patches for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

This development serves as a reminder that the cybersecurity landscape is constantly evolving. As AI tools become more prevalent, it’s essential to adapt and reassess our approaches to vulnerability discovery and disclosure. For security researchers, this may mean being more selective about which bug bounty programs they participate in or exploring alternative methods for identifying vulnerabilities.

In the meantime, Google encourages researchers to submit reports through other VRP programs or pursue the Patch Rewards Program. While this may not be an ideal solution, it’s a temporary fix that allows researchers to continue contributing to the security of open-source projects maintained by Google. As we navigate the challenges posed by AI-generated reports, one thing is clear: bug bounty programs must evolve to keep pace with the changing landscape of vulnerability discovery.


Source: Bleeping Computer — 2026-10-05