Google Pauses Open Source Bug Bounty Over Flood of AI Reports
Google has paused its open source bug bounty program starting October 1 because of a sharp rise in automated submissions. Most of them turned out to be invalid.
Google has temporarily paused its Vulnerability Rewards Program (VRP) for Open Source Software. The program pays outside researchers for finding security flaws in Google's open source projects. The pause started on October 1, 2026. Google says it saw a sharp rise in automated reports. Most of these reports were wrong or irrelevant. Some were based on bad information. Others described vulnerabilities that did not exist at all. This created a lot of noise for engineers and maintainers, the people who keep open source software running and updated. They had to sort through far too many reports. During the pause, Google will point participants to its other bug bounty programs. The company plans to relaunch the VRP in an updated form in the first quarter of 2027.
This does not mean AI tools are the problem. It means people were not checking their reports carefully before sending them to Google. If they had reviewed each report by hand before submission, most of the invalid ones probably would never have reached an engineer's inbox. A simple manual check before sending could have been enough to avoid this problem, without shutting down the whole program.
Source: techcrunch.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles