Google Freezes Open Source Bug Bounty Program Over Influx of Invalid AI Submissions
A surge in automated vulnerability reports containing hallucinations led Google to pause the reward program until 2027.

Google has suspended its Open Source Software Vulnerability Rewards Program following an influx of low-quality automated filings, as reported by TechCrunch AI (https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/).
The company paused the bounty initiative on Oct. 1, 2026, and announced on its website and X that it plans to provide an update in the first quarter of 2027. The program provides financial rewards to external security researchers who locate vulnerabilities across Google's open-source projects.
Google cited operational strain caused by synthetic submissions for the decision. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said in an official statement.
The inundation of submissions created a triage bottleneck. According to reporting from Tom's Hardware cited by TechCrunch AI, Google engineers and open-source maintainers faced an unsustainable volume of invalid reports, including filings detailing hallucinated vulnerabilities.
While the open-source program remains offline pending the 2027 review, Google directed security researchers toward its other active vulnerability reward tracks.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



