Google suspends open-source bug bounty program after being overwhelmed by AI spam.

The triage burden stems from reports that can appear plausible but concern unreachable code, non-working exploits, or flaws with no meaningful security impact; each still requires a human to investigate.
Google’s March 2026 rule changes included requiring stronger evidence for some product vulnerabilities and reducing rewards for lower-priority project tiers.
The reports say the volume of automated findings has also affected Linux: maintainers faced a surge of bogus CVE filings, and the Linux project dropped support for older network drivers.
The pause highlights a trade-off: AI may help researchers uncover real vulnerabilities—Google has explored that potential with its Big Sleep security agent—but it can also make it cheap to generate candidate reports faster than people can verify them.
Google shut down new submissions to its open-source bug bounty program on October 1, 2026, after AI-generated reports flooded the system Benzinga. The Open Source Software Vulnerability Reward Program was overwhelmed by automated findings—most fake or harmless—that drained reviewer time without catching real security flaws Newsy Today.
The pause does not affect reports filed before the cutoff or supply-chain disclosures. Google expects to revise the program and share an update in early 2027, but has not said when new submissions will reopen iHeart.
Each bogus submission still demands human review—even if it targets unreachable code, contains non-working exploits, or describes flaws with zero security impact Newsy Today. This triage burden forces maintainers to spend hours on useless findings instead of real threats.
Google tightened rules in March 2026 by requiring stronger evidence for vulnerabilities and cutting rewards for lower-priority projects Benzinga. But the AI tools kept firing anyway, ignoring the guardrails.
Open-source communities beyond Google felt the same pain. Linux maintainers faced a surge of false CVE (vulnerability) reports so severe the project dropped support for older network drivers to reduce the filing surface Benzinga.
The wave exposed how cheap AI makes candidate report generation. Researchers now produce findings faster than humans can validate them—a speed mismatch that turns bug bounties into noise.
AI tools like Google's Big Sleep security agent can uncover real vulnerabilities that humans miss Newsy Today. The upside is genuine—researchers benefit from AI-assisted discovery.
But the same AI capability makes spam cheap to produce at scale. Until Google redesigns its intake process, the program stays closed. Researchers seeking bounties can submit to Patch Rewards or Google Cloud's separate program in the meantime.
Publishers
19
Articles
159
Reach
178