Google pauses open-source bug bounties after AI slop floods reviewers

AI spam just broke Google’s open-source security program.

Google has paused its Open Source Software Vulnerability Rewards Program after a flood of bad AI submissions overwhelmed its reviewers, according to TechCrunch. The company pulled the plug on October 1, citing a "significant rise" in automated submissions that were overwhelmingly invalid. Tom's Hardware reported that Google engineers and open-source maintainers were drowning in reports containing hallucinations and fake flaws.

Why it matters: Bug bounties exist to pay human researchers for finding real security holes. When spammers use AI to pump out thousands of hallucinated reports, maintainers waste hours triaging junk instead of fixing actual software flaws.

Know this: Google expects the freeze to last until the first quarter of 2027, when it promises to provide an update. In the meantime, participants are being told to focus on Google's other bug bounty programs.

Turns out spamming fake bugs with AI is much faster than reviewing them.