← Home

Google Freezes Its Open-Source Bug Bounty Program Amid AI Submission Flood

Google Freezes Its Open-Source Bug Bounty Program Amid AI Submission Flood

On October 1, Google suspended the intake of new vulnerability reports in its Open Source Software Vulnerability Rewards Program (OSS VRP), announcing via an official social media post that the pause would last until the first quarter of 2027. The stated reason was "a significant rise in automated submissions, the vast majority of which are not valid." What has emerged at the OSS VRP is the latest visible symptom of what security researchers have been warning about for more than a year: automated report generation using large language models is degrading the quality of bug bounty programs, and Google's open-source bounty program has become the most recent casualty.

The OSS VRP is one of the most important open-source security programs in the world. Unlike Google's main VRP — which covers proprietary products like Search, YouTube, and Google Cloud — the OSS VRP is specifically scoped to third-party open-source projects, including libraries, frameworks, and tools that power internet infrastructure. Google pays external researchers for real vulnerabilities found in thousands of open-source projects, from Chromium to Kubernetes. In 2025, Google paid over $17 million in rewards via the VRP, with 747 active researchers. The open-source program accounts for a significant share of that total.

The problem began when researchers discovered that bug bounty report submissions could be automated using LLMs. Tools such as Claude, Gemini, and specialized models were configured to analyze source code, identify vulnerability patterns, and generate reports in a format compatible with the VRP. Initially, these systems produced mixed results — some submissions were valid, but many contained errors, incorrect trigger conditions, or even vulnerabilities that never existed. What had been an artisanal human effort became an automated production line.

Google did not provide specific numbers on the volume of submissions, but industry sources indicate that the ratio of invalid reports jumped from an already high baseline to more than 90% over the past several months. This means that for every genuine report, OSS VRP reviewers had to discard a dozen or more AI-generated submissions — many of them containing what Google termed "hallucinations": descriptions of exploitation paths that appear plausible at a glance but are technically impossible upon closer inspection.

Google's response was hardly surprising. In addition to the suspension, the program tightened its evidence requirements for certain types of reports, particularly memory corruption flaws in high-priority projects. The idea is to filter out the bots: requiring more rigorous proofs makes automated generation of valid reports harder, since AI still struggles to produce coherent functional proofs without access to a real execution environment.

But the measure raises a broader question. Bug bounty programs depend on the assumption that the researchers feeding them are human and committed. If the barrier to entry falls to zero — anyone can run a local script against an open-source repository and submit reports automatically — the economic model of the bug bounty collapses. Google paid $17 million in 2025 to compensate human researchers who had devoted hundreds of hours to vulnerability discovery. If most of those discoveries can be replicated by a script running overnight, the reward value shrinks for the human participant.

There is an ironic contrast here. The same Google that built an "AI-based bug hunter" which found over 20 real vulnerabilities in 2025 — widely reported as progress in automated security — is now paralyzed by the indiscriminate use of AI by third parties. The technology Google developed for itself is being used by others in a way that overwhelms its own security infrastructure. The case of the researcher who earned $500,000 in 90 days using Claude as an automated pentesting engine illustrates precisely this paradox: AI can find bugs, but at massive scale, it finds more ghosts than real vulnerabilities.

What we are witnessing is an inevitable transition. As AI models improve, bug bounty programs will have to adapt — whether through mandatory identity verification, challenges requiring complex human interaction, or the creation of a new reward model that distinguishes between AI-assisted discovery and genuine discovery. Google's temporary suspension of the OSS VRP is only the first chapter of this reengineering.

Sources: TechCrunch, BleepingComputer, CyberSecurityNews

✓ Independent sources cross-checked and verified before publishing