Google Pauses Open Source Bug Bounty Program Until 2027 Amid Influx of ‘AI Slop’ and Invalid Submissions

MOUNTAIN VIEW, California — In a dramatic escalation of a growing crisis across the cybersecurity industry, Google has officially announced the suspension of its Open Source Software Vulnerability Rewards Program (OSS VRP). Citing an unprecedented surge in automated, low-quality, and AI-generated bug reports, tech giant Google took the drastic step to press pause on the initiative to protect its engineering resources from being completely overwhelmed.

The suspension, which took effect on October 1, brings a temporary halt to a program that has long served as a critical pillar in securing the open-source ecosystem. According to company statements, the program will remain shuttered through the remainder of the year, with a formal review and status update promised for the first quarter of 2027.

While Google’s core product vulnerability reward programs remain active, the decision to freeze open-source security submissions underscores a grim new reality: the democratization of artificial intelligence has gifted malicious actors and opportunistic bounty hunters alike with the tools to mass-produce deceptive, hallucinated, and entirely useless security vulnerability claims.


Main Facts

The core of the issue lies in the overwhelming volume of submissions inundating Google’s security triage teams and open-source software (OSS) maintainers. For years, bug bounty programs have relied on crowdsourced security researchers—often referred to as "white-hat hackers"—to identify and responsibly disclose security flaws in exchange for cash rewards. However, the proliferation of generative AI tools has fundamentally broken the economics and operational viability of these programs.

  • The Suspension Date: Google officially paused the Open Source Software Vulnerability Rewards Program (OSS VRP) on October 1.
  • The Expected Return: Google has stated that it will evaluate the landscape and provide a program update in the first quarter of 2027.
  • The Root Cause: A massive, unmanageable spike in automated submissions, the vast majority of which are completely invalid or driven by AI hallucinations.
  • The Impacted Ecosystem: The pause specifically targets Google’s open-source software security bounty program, though the company’s other proprietary product bug bounty programs remain operational for now.
  • The Warning Signs: Security experts have been sounding the alarm for over a year regarding the influx of "AI slop" into vulnerability reporting pipelines, straining human reviewers who must manually verify every claim.

Chronology: How the "AI Slop" Crisis Overwhelmed Open Source Security

To understand how Google reached the tipping point of suspending one of its flagship security initiatives, it is necessary to examine the rapid evolution of generative AI tools and their intersection with cybersecurity crowdsourcing.

Early 2024: The Rise of AI-Assisted Code Analysis

As large language models (LLMs) became more sophisticated in code comprehension, security researchers began integrating AI tools into their workflows. Initially, this was seen as a positive development. AI could quickly parse massive codebases, flag potential anomalies, and accelerate the discovery of complex vulnerabilities.

However, the barrier to entry for participating in bug bounty programs dropped precipitously. Individuals with limited coding experience or deep technical understanding realized they could prompt an AI model to scan open-source repositories and automatically generate vulnerability reports.

Mid-2024 to Early 2025: The Tides of "AI Slop"

By the middle of 2025, security conferences and industry publications began tracking a disturbing trend. Security teams at major technology companies reported being flooded with thousands of low-effort, AI-generated reports—colloquially dubbed "AI slop."

Unlike human researchers who typically perform deep-dive analysis, verify exploits, and write comprehensive proof-of-concept code, AI tools frequently hallucinate non-existent vulnerabilities. They misinterpret benign code patterns as critical Remote Code Execution (RCE) flaws or SQL injections, spewing out authoritative-sounding yet entirely fabricated reports.

TechCrunch and other industry outlets reported as early as mid-2025 that cybersecurity experts were reaching a breaking point. Triage teams were spending more time filtering out algorithmic garbage than investigating legitimate security threats.

October 2025: Google Draws the Line

By the final quarter of 2025, the burden on Google engineers and open-source maintainers became untenable. Recognizing that the signal-to-noise ratio in the OSS VRP had degraded past the point of functional utility, Google made the executive decision to pull the plug temporarily.

In official notices posted to X (formerly Twitter) and the official Google Bug Hunters platform, the company announced that the program would go on hiatus. Rather than attempting to patch a broken triage pipeline while under constant siege from automated scripts, Google chose to shut the doors until a sustainable filtering mechanism can be developed.


Supporting Data and Industry Context

Google’s decision does not occur in a vacuum; it is part of a broader, systemic crisis facing the global cybersecurity community. Bug bounty platforms, corporate security departments, and open-source maintainers are all grappling with the fallout of democratization-gone-wrong in the age of generative AI.

The Math of Triage Overload

In a healthy bug bounty program, a high volume of submissions is typically viewed as a sign of robust community engagement. However, the nature of AI submissions has inverted this metric.

According to industry estimates shared by various platform administrators, automated and AI-generated reports often account for upwards of 80% to 90% of total submissions in targeted programs. Each submission—even if blatantly false—requires a human security engineer to:

  1. Open the ticket and read the description.
  2. Review the referenced code repository.
  3. Test the alleged proof-of-concept (PoC).
  4. Determine whether the vulnerability is real or an AI hallucination.
  5. Communicate with the submitter (who often pushes back using automated AI-generated rebuttals).

When multiplied by thousands of submissions a week, this process consumes thousands of hours of highly skilled engineering labor. For open-source maintainers—who often volunteer their time or work underfunded—this administrative onslaught represents an existential threat to project maintenance.

Open Source Software Vulnerabilities: A Unique Target

Open-source software presents an inviting target for bad actors and lazy bounty hunters alike. Because the source code is entirely public, automated tools can ingest entire ecosystems (such as Python’s PyPI, Node.js’s npm, or Linux kernel modules) without restriction.

Furthermore, because open-source projects rely heavily on decentralized communities rather than centralized corporate security teams, they lack the dedicated SOC (Security Operations Center) workforces required to handle high-volume triage. When Google’s OSS VRP rewarded researchers for finding flaws in these shared dependencies, it unintentionally created a lucrative gold rush that attracted automated spam operations looking for quick payouts.


Official Responses and Statements

Google’s leadership and security teams have been transparent—albeit concise—regarding the motivations behind the suspension.

In updates published to the official Google Bug Hunters rules page and broadcast via the @GoogleVRP handle on X, the company stated:

"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

The company emphasized that the pause is strictly a temporary measure aimed at re-evaluating program rules, submission guidelines, and technical filters. Google engineers and program managers are reportedly using the downtime extending through 2026 to build more robust, automated detection systems capable of identifying and rejecting AI-generated hallucinated reports before they ever reach a human reviewer’s desk.

While shutting down the open-source program, Google has sought to direct legitimate researchers toward its remaining ecosystems. In its official communications, the company noted:

"In the meantime, participants are encouraged to consider Google’s other bug bounty programs."

However, security analysts point out that if AI slop continues to proliferate unchecked, Google’s proprietary product VRPs—covering platforms like Android, Chrome, and Cloud—may soon face the exact same reckoning.


Implications for the Future of Cybersecurity

Google’s suspension of its Open Source VRP serves as a watershed moment for the cybersecurity industry. It forces a fundamental re-examination of how organizations source vulnerability intelligence, reward security research, and manage the administrative burdens of the AI era.

1. The Death of Low-Effort Bug Hunting

For years, the "bug bounty side hustle" has been promoted as an accessible way for tech-savvy individuals to earn substantial bounties. However, the era of casually running an LLM script against a codebase and submitting hundreds of speculative reports is coming to an end.

Major platforms and enterprise programs are rapidly implementing stricter filters, rate limits, financial penalties for repeated invalid submissions, and reputational scoring systems that permanently ban repeat offenders of AI spam.

2. The Strain on Open-Source Security

The open-source community relies on a fragile web of trust and decentralized contributions. When corporate giants like Google step back from incentivizing vulnerability discovery—even temporarily—it leaves open-source maintainers more vulnerable to genuine zero-day exploits that go unreported while triage teams catch their breath.

Conversely, forcing maintainers to waste countless hours wading through AI garbage was already pushing many open-source contributors toward burnout. The pause, while painful, may ultimately provide necessary breathing room for the ecosystem to reorganize.

3. The Need for AI Counter-Intelligence

Ironically, solving the problem of AI-generated bug reports will likely require the deployment of advanced AI defenses. Security platforms are heavily investing in machine learning models specifically trained to detect the stylistic markers, hallucination patterns, and logical inconsistencies inherent in LLM-generated security write-ups.

Until these defensive systems reach maturity, human security teams will remain vulnerable to being drowned out by the sheer volume of algorithmic noise.


Conclusion

Google’s decision to freeze its Open Source Software Vulnerability Rewards Program until 2027 is a stark reminder that technological progress is a double-edged sword. While generative artificial intelligence has unlocked new frontiers in software development and analysis, it has simultaneously armed bad actors and opportunistic spammers with the capability to weaponize volume against the defenders of the digital realm.

As the industry watches to see how Google restructures its program ahead of its planned 2027 relaunch, one thing is abundantly clear: the Wild West era of bug bounties is officially over. Moving forward, the cybersecurity community must adapt to a landscape where distinguishing between human ingenuity and artificial intelligence "slop" is the primary battleground of digital defense.