Live
Abstract illustration of dozens of translucent teal fragments raining onto a gridded isometric slab, with a single bright fragment passing through a beam beneath it
Privacy & Security

Google Paused Its Open-Source Bug Bounty Over a Flood of Bad AI Reports

Since Oct. 1, Google has stopped taking new product vulnerability reports through its Open Source Software Vulnerability Reward Program, the bounty that has paid researchers between US$100 and US$31,337 (about CA$139 to CA$43,560) per bug since 2022. The reason, in a post Google made on X quoted by BleepingComputer: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”

Read plainly, that means machines are writing bug reports, most of them are wrong, and paying humans to sort them stopped making sense. TechCrunch reported the freeze on Oct. 4, citing Tom’s Hardware’s account of Google engineers and maintainers buried in reports full of AI hallucinations.

It is a partial shutdown, and the details matter if you hunt bugs for a living.

What Google’s OSS VRP pause covers, and what still pays

The open-source program has two halves. Product vulnerabilities, meaning flaws such as memory corruption in parsers or path traversal in projects like Go, Angular and Protocol Buffers, are the half that closed. “As of October 1 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP,” Google said, as quoted by ITPro.

Supply-chain compromise reports, the kind that show how an attacker could tamper with a Google repository or its build pipeline, are not affected, and neither is anything submitted before Oct. 1, BleepingComputer reports. Those supply-chain reports are where the top US$31,337 reward lives, with payouts starting at US$3,133.70 depending on the project’s tier, according to The Cyber Express.

Google is pointing researchers elsewhere in the meantime: the Cloud VRP for flaws in Google Cloud’s open-source repositories, the AI VRP, and the Patch Rewards Program, which pays for security fixes rather than findings, Infosecurity Magazine reports. Google has not promised a relaunch date. “We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027,” the company said, per Help Net Security. An update is not a redesign, and it is certainly not a reopening.

Curl saw this coming in January

Google is the biggest name to buckle, not the first. Daniel Stenberg, who leads the curl project, ended its HackerOne bug bounty on Jan. 31 after nearly seven years. In his post explaining why, he tallied 87 confirmed vulnerabilities and more than US$100,000 (about CA$139,000) paid out, then described what changed: in 2024 more than 15% of submissions were confirmed as real, and in 2025 that fell below 5%.

Timeline: Jan. 31, 2026, curl ends its HackerOne bug bounty; Mar. 17, Google, Amazon, Anthropic, Microsoft/GitHub and OpenAI pledge US$12.5M to help maintainers; Sept. 19, Intel swaps its paid bounty for an unpaid disclosure program (Tom's Hardware report); Oct. 1, Google stops taking OSS VRP product bug reports; Q1 2027, Google's promised update. curl's confirmed-report rate fell from over 15% in 2024 to under 5% in 2025.
Google’s Oct. 1 pause follows curl’s January shutdown and Intel’s move to unpaid disclosure. Graphic: prompt/power

“Not even one in twenty was real.” Daniel Stenberg, curl lead maintainer

Intel went further in September, replacing a bounty that paid up to US$100,000 per flaw with an Intigriti disclosure program that offers no rewards at all, Tom’s Hardware reported Sept. 19. Intel gave no reason, so the AI link there is speculation, not a stated cause.

The money problem is easy to see. A bad report costs its sender a prompt. It costs a maintainer an afternoon of reproducing, rebutting and closing it. Bounties put a price on the sender’s side of that trade and nothing on the other.

The same AI is finding real bugs

Here is the awkward part for Google. Its own pitch for its newest model, made Sept. 30, is that “Argon can autonomously find, validate, and patch critical software vulnerabilities,” according to the Gemini 4 Argon announcement. In March, Google pointed to its DeepMind tools Big Sleep and CodeMender as AI that detects and fixes flaws, in a post announcing a US$12.5 million (about CA$17.4 million) fund it put up with Amazon, Anthropic, Microsoft/GitHub and OpenAI, run through the Linux Foundation’s Alpha-Omega and OpenSSF to help maintainers cope. Anthropic’s red team measures the same skill in rival models, as we reported when it rated a Chinese open-weight model’s hacking skills.

Google graphic reading Total Reward in 2025: 17.1 million
Google’s vulnerability reward programs paid a record US$17.1 million in 2025. Image: Google

Our read: the gap is validation. A frontier model run by a team that checks its output can find real bugs. The same class of model, pointed at a bounty page by someone hoping for a payout, produces confident write-ups of bugs that don’t exist. The bounty can’t tell the two apart until a human has done the work.

None of this dents Google’s overall spending. Its vulnerability reward programs paid a record US$17.1 million (about CA$23.8 million) to 747 researchers in 2025, up 40% on 2024, and US$81.6 million since 2010, Google said in March.

What it means for researchers and maintainers

  • If you found a product bug in a Google open-source project after Oct. 1: it won’t earn an OSS VRP reward. Check whether it qualifies for the Cloud VRP or AI VRP, or submit a fix through Patch Rewards.
  • If you submitted before Oct. 1: Google says those reports are unaffected.
  • If you maintain an open-source project: expect the reports Google no longer pays for to land somewhere else, possibly on you. Publishing a policy on AI-assisted reports, and requiring a working proof of concept, is now common practice.

Google’s next word is due by the end of March 2027. Until then, the US$31,337 top prize, a figure that spells “eleet” in hacker numerals, is reachable only through the supply-chain door.

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. Thomson Reuters Won the First AI Training Appeal. Footnote 7 Is the CatchOct 7
  2. The Family Safe Word: How to Beat AI Voice-Clone Emergency ScamsOct 7
  3. Reflection AI’s Beam, Explained: The 501B Open-Weight Model Aimed at ChinaOct 7
  4. Your SSN or SIN Leaked in a Breach? Do These 8 ThingsOct 7
  5. Apple’s Oct. 13 Event Rumour, Plus iPhone Duo Pre-Order Dates for CanadaOct 7

Leave a Reply

Your email address will not be published. Required fields are marked *