Google Pauses Open Source Bug Bounty Program Until 2025, Citing Surge in AI-Generated Submissions
By admin | Oct 04, 2026 | 1 min read
Google has decided to hit pause on its open source bug bounty initiative, and the company is pointing the finger at a surge in AI-generated submissions as the reason. The program in question is Google's Open Source Software Vulnerability Rewards Program, which had been compensating security researchers for uncovering flaws in the company's open source software.
EMBED_PLACEHOLDER_0
The announcement came through posts on X as well as on the program's official website. According to those communications, the bug bounty program went on hold as of October 1, and Google has committed to sharing "an update" during the first quarter of 2027.
EMBED_PLACEHOLDER_1
The flood of problematic reports apparently became too much to handle. Google engineers and open source maintainers found themselves buried under a deluge of submissions that were either invalid or riddled with hallucinations, according to Tom's Hardware.
In Google's own words, "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
While the program remains suspended, Google is directing participants toward its other bug bounty offerings as an alternative outlet for their security research efforts.
Comments
Please log in to leave a comment.
No comments yet. Be the first to comment!