Skip to content
Breaking:

Google Freezes Open Source Bug Bounty Program Over Influx of Invalid AI Submissions

A surge in automated vulnerability reports containing hallucinations led Google to pause the reward program until 2027.

By The Company Wire3 min read
Share
Google — Google Freezes Open Source Bug Bounty Program Over Influx of Invalid AI Submissions
Google — Google Freezes Open Source Bug Bounty Program Over Influx of Invalid AI Submissions. Photo: TechCrunch AI.

Google has suspended its Open Source Software Vulnerability Rewards Program following an influx of low-quality automated filings, as reported by TechCrunch AI (https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/).

The company paused the bounty initiative on Oct. 1, 2026, and announced on its website and X that it plans to provide an update in the first quarter of 2027. The program provides financial rewards to external security researchers who locate vulnerabilities across Google's open-source projects.

Google cited operational strain caused by synthetic submissions for the decision. "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said in an official statement.

The inundation of submissions created a triage bottleneck. According to reporting from Tom's Hardware cited by TechCrunch AI, Google engineers and open-source maintainers faced an unsustainable volume of invalid reports, including filings detailing hallucinated vulnerabilities.

While the open-source program remains offline pending the 2027 review, Google directed security researchers toward its other active vulnerability reward tracks.

Sources

  1. TechCrunch AI

Company: Google

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.