Cybersecurity

Google pauses its open-source bug bounty after a flood of fake AI reports

Susan Hill
Add us on Google

Google has stopped accepting new reports of security flaws in its open-source projects through the bug bounty that paid outside researchers to find them. The reason is a flood of submissions written by AI tools, and most of them describe bugs that do not exist.

That reaches well beyond Google. The Go programming language, the Angular web framework, the Bazel build system and Protocol Buffers sit underneath millions of apps and websites, and the bounty was one of the ways outside researchers got paid to find their weak spots before attackers did. For now, that door is half closed.

A bug bounty runs on a simple bargain. Anyone can study the code, and if they find a real vulnerability and report it privately, the company pays. Google’s Open Source Software Vulnerability Reward Program paid between $100 and $31,337 per report, the top figure a wink at “elite” in old hacker slang. Every submission lands on the desk of a security engineer, who has to reproduce the problem before anyone gets paid.

That human step is where the system jammed. In its notice, Google said the pause came from “a significant rise in automated submissions, the vast majority of which are not valid.” Reports produced by AI models can read like expert work, with code snippets, step-by-step attack paths and confident severity ratings. Security researchers who track the problem describe invented exploit paths, wrong assumptions about how the code behaves, and claims that a vulnerable function can be reached when it cannot. Each one still costs an engineer time to disprove.

The pause is narrower than it first sounds. Google still takes supply-chain reports, the kind that flag a compromised dependency or a hijacked build pipeline, and it will finish handling every product report submitted before the cutoff. Its Patch Rewards Program, which pays up to $15,000 for fixes that harden important open-source projects, keeps running, and some flaws in Google Cloud repositories can still go through the separate Cloud program.

There is a cost, though. A pause also turns away the careful human researchers who use AI as one tool among many, and a real flaw found in the meantime has one less paid route to Google’s engineers. The company has not said how many reports it received, what share came from AI, or how it will tell good automated findings from bad ones when the program returns.

Google is not the first to hit this wall. Daniel Stenberg, lead maintainer of curl, the data-transfer tool built into billions of devices, shut down that project’s bug bounty in January 2026 after AI-generated reports kept piling up. In March, Anthropic, Google, Microsoft, GitHub, OpenAI and AWS pledged $12.5 million to the Open Source Security Foundation and its Alpha-Omega project, with AWS warning that AI-generated reports were overwhelming open-source maintainers.

The pause took effect on October 1, and Google has promised an update on a reworked program in the first quarter of 2027. Until then, researchers who find a product flaw in Google’s open-source code are being pointed to the company’s other reward programs.

The tools that promised to find bugs faster have ended up burying the people who check them. For now, the scarcest thing in open-source security is a person with enough time to read the report.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.