Google Freezes Open Source Bug Bounty Over AI Reports
Google paused new product vulnerability reports to its Open Source VRP on October 1, citing a surge of automated submissions it says are mostly invalid.

Google stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Rewards Program on October 1, and the stated reason is a single sentence: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." The company plans an update in the first quarter of 2027, according to TechCrunch.
Google maintains Go, Angular and Fuchsia, and it says it can no longer sort the reports coming in.
TL;DR
- New product vulnerability reports to the OSS VRP have been closed since October 1, 2026; reports filed before that date are still handled
- Supply-chain vulnerability reports, the Cloud VRP and the Patch Rewards Program stay open
- Google gave no numbers on how many submissions it received or how many were invalid
- curl, the Internet Bug Bounty and now Google have each cut payouts for the same reason in nine months
What Google Claimed and What It Left Out
| Claim | Source | What's missing |
|---|---|---|
| Submissions rose "significantly" | Google notice | No volume, no baseline |
| "Vast majority" are invalid | Google notice | No invalid rate, no sample |
| Pause lasts until Q1 2027 update | Google notice | No criteria for reopening |
| Supply-chain reports stay in scope | CyberPress | No definition of the boundary in the notice itself |
Google announced the freeze on X and on its Bug Hunters site. The program launched in 2022 and covers projects such as Go, Angular and Protocol Buffers, sorted into four tiers from OT0 to OT3, per Help Net Security.
The OSS VRP landing page on Google's Bug Hunters site, which describes Golang, Angular and Fuchsia as flagship projects.
Source: bughunters.google.com
What Methodology Would Tell Us
Without Google's figures, the claim can't be checked. Compare curl's maintainer Daniel Stenberg, who published his. When he ended curl's bounty in January, he reported that the confirmed-vulnerability rate had fallen from over 15% historically to below 5% in 2025. The program had found 87 vulnerabilities and paid over $100,000 across seven years. That is a measurable decline, and it gives outsiders something to argue with. Google offered an adjective.
Why AI Reports Are Expensive to Reject
Help Net Security's summary of the problem is that AI-written reports look convincing while containing invented exploit paths, wrong assumptions about what the source code does, or claims that a vulnerable function is reachable when it isn't.
That last failure is the expensive one. A reviewer can't dismiss a report by reading its first paragraph. They have to trace the call path, build the scenario and fail to reproduce it. A fabricated report costs the maintainer about as much as a real one, and it costs the submitter almost nothing.
CyberPress reports that Google's remaining programs now demand realistic exploit paths. A claim that a malicious contributor could alter a repository, for instance, has to show how the attacker gets past pull-request approval. Reports that depend only on a maintainer approving bad code are classed as insider risk, not compensable findings.
The Reward Tiers Complicate the Picture
CyberPress lists historical tiers of $3,133.70 to $31,337 for OT0 flagship projects, $1,337 to $13,337 for OT1, and $500 to $3,133.70 for OT2. Help Net Security says the current reward table lists no amounts for product vulnerabilities. The two accounts don't agree, and we couldn't resolve it from Google's pages, so treat the dollar figures as the pre-pause schedule rather than a live offer.
Either way, the incentive is plain. A payout of up to five figures per report makes it rational to point a model at every in-scope repository and submit whatever comes out.
This Is the Third Program to Blink
The pattern is no longer isolated:
Jan 2026 - curl ends its bug bounty on January 31. Reports now go through GitHub private reporting or email, with no money attached.
Apr 2026 - HackerOne pauses payouts from the Internet Bug Bounty, which had awarded over $1.5 million since 2012. CSO reported that Node.js would no longer receive bounty funding, and that Google had already paused AI-created submissions to the OSS VRP in the preceding weeks.
Oct 2026 - Google closes new product vulnerability reports outright.
The money side has been moving too. In March, seven companies including Google put $12.5 million into OpenSSF and Alpha-Omega to build triage tooling for maintainers, and a separate group launched a permanent endowment for open source. Neither announcement named a specific tool or date for relief.
Should You Care?
If you maintain a small project, yes, because the cost has moved onto you. Big programs can pause. A solo maintainer can't, and without a bounty to close, the reports keep arriving by email and GitHub issues.
If you do legitimate AI-assisted research, the pause hurts you too. Google's wording doesn't separate a model-created guess from a model-assisted finding that a human reproduced. Both land in the same closed queue. Google points researchers to its other reward programs while the OSS VRP is frozen.
Our read: a pause is the cheapest response available, and it admits that filtering is harder than paying. A better design would charge for the cost it creates, through reproducible proof-of-concept requirements, submitter reputation or a refundable deposit. Google hasn't said which, if any, it will adopt in Q1. Until it does, the open question is what a researcher who reproduced a real Angular bug on October 2 is supposed to do with it.
Sources:
- TechCrunch - Google froze its open source bug bounty program
- Help Net Security - AI slop submissions force Google to freeze its open-source bug bounty
- CyberPress - Google tightens open-source bug bounty rules
- CSO Online - Internet Bug Bounty program hits pause on payouts
- Daniel Stenberg - The end of the curl bug bounty
