Posted:

Google froze its open source bug bounty program due to a âÂÂsignificant riseâ in AI submissions
Blaming a âÂÂsignificant riseâ in AI submissions, Google has paused its open source bug bounty program until next year.
Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs. Looks like thatâÂÂs the issue confronting GoogleâÂÂs Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the companyâÂÂs open source software.
In posts on X and the program website, Google said the bug bounty program was paused as of October 1, with a promise to provide âÂÂan updateâ in the first quarter of 2027. According to TomâÂÂs Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations.
âÂÂThis pause is due to a significant rise in automated submissions, the vast majority of which are not valid,â the company said.
In the meantime, participants are encouraged to consider GoogleâÂÂs other bug bounty programs.
