Google has paused its bug bounty for open source software, the OSS Vulnerability Rewards Program. Since October 1 the program no longer accepts product flaw submissions. Google’s own wording for the reason: “a significant rise in automated submissions, the vast majority of which are not valid.”
Since October 1, nothing gets through
TechCrunch reported the pause on Sunday, Tom’s Hardware on Saturday. The facts are short: product vulnerability submissions are stopped, the restart is planned for the first quarter of 2027, and Google suggests researchers look at other bounty programs in the meantime.
Tom’s Hardware fills in what sat behind it. Google engineers and open source maintainers could not keep up with the volume, because most of what came in was either invalid or carried hallucinations.
The reason fits in half a sentence
“Automated submissions” is a polite way to put it. These are reports a model wrote that look exactly like vulnerability reports: title, reproduction steps, severity assessment, code snippet. Everything in the right place, and none of it necessarily true.
The nasty part is the cost of checking. A real report and an invented one take the same human the same half hour before they know which one they were holding. Only the invented kind can be produced in bulk. When one side scales and the other doesn’t, the system tips over eventually — and here it did.
A reporting system choking on its own success
TechCrunch points out that a warning about this ran back in July 2025. A year and a half on, the warning has turned into a shutdown, and it happened at Google, the organisation with more resources than anybody else in that position.
What stays with me is this: bounty programs are one of the few places where open source gets outside money and attention for security. When they buckle under a flood of plausible-looking text, the cost doesn’t land on Google. It lands on the projects underneath. And it is the same mechanism we saw in late September with GLM-5.3 writing exploits without safeguards, just approached from the other side. There, models cut the cost of a real attack. Here, they cut the cost of something that merely looks like a tip about one. Both push the load onto the same handful of people who have to look at it in the end.
A quarter of downtime buys time and nothing else. If Q1 2027 arrives with nothing but a reopened form, the same thing starts over.
Sources: