Google halts open-source bug bounty program amid AI spam surge

Google’s Open-Source Bug Bounty Program Halted Amid AI-Generated Spam Surge

Google has temporarily suspended its Open Source Software Vulnerability Rewards Program (OSS VRP) after being inundated with automated submissions, most of which are invalid. This move is the latest in a string of cybersecurity programs to be impacted by the increasing use of artificial intelligence (AI) tools to generate reports.

The OSS VRP was launched in August 2022 as an incentive for security researchers to identify vulnerabilities in open-source projects maintained by Google, including popular frameworks like Golang and Angular. The program offered rewards ranging from $100 to a maximum of $31,337 for identifying critical flaws that could impact the software supply chain.

However, over the past few months, Google has seen a significant surge in automated submissions, which have overwhelmed its bug bounty program. According to the company, these submissions are largely invalid and generated by AI tools designed to exploit the system. This development has prompted Google to temporarily halt submissions to the OSS VRP while it works on addressing this issue.

The suspension of the OSS VRP is not a permanent decision, but rather a temporary measure aimed at reformatting the program to prevent abuse by automated tools. In an update on its Bug Hunters website, Google assured researchers that they can still submit security patches for open-source software through the Google Patch Rewards Program (which offers bounties of up to $15,000) or report vulnerabilities in Google Cloud open-source repositories that affect Cloud products.

Google’s move is not isolated; several other cybersecurity programs have faced similar challenges due to AI-generated reports. For instance, the maintainer of the curl command-line utility and library ended its HackerOne security bug bounty program after being overwhelmed by a massive stream of invalid vulnerability reports generated by AI tools. Intel also recently removed financial rewards for security flaws in its software, firmware, hardware, and services reported on its Intigriti bug bounty program.

The increasing use of AI tools to generate reports has significant implications for the cybersecurity industry. While these tools can help streamline the process of identifying vulnerabilities, they also create new challenges. As Microsoft warned earlier this year, AI-powered attacks are becoming more prevalent, leading to an increase in vulnerability discovery and operational demands.

To mitigate these risks, security professionals must be aware of the potential for AI-generated reports and take steps to validate their authenticity. This includes checking for inconsistencies, verifying the identity of the reporter, and ensuring that the report is submitted through legitimate channels.

In conclusion, Google’s decision to temporarily suspend its OSS VRP serves as a reminder of the challenges posed by AI-powered attacks in the cybersecurity industry. As these threats continue to evolve, it is essential that security professionals stay vigilant and adapt their strategies to address them effectively. By doing so, they can help prevent the exploitation of vulnerabilities and keep sensitive information secure.


Source: Bleeping Computer — 2026-10-05