Google Freezes Open Source Bug Bounty After Surge in AI Spam Reports

Google Freezes Open Source Bug Bounty After Surge in AI Spam Reports

TL;DR

  • Google has temporarily paused submissions to its open-source bug bounty program after being flooded with low-quality, AI-generated vulnerability reports that drain triage resources.
  • The surge of plausible-looking but invalid AI slop is overwhelming security teams and crowding out legitimate researchers, delaying payouts for real bugs.
  • The freeze is a warning sign for the entire bug bounty industry, with other vendors like Mozilla, curl, and HackerOne already reporting similar problems and weighing stricter verification rules.

What Actually Happened

Google has hit pause on one of its most respected security initiatives. In an update shared via its Google Bug Hunters program, the company confirmed it is temporarily freezing new submissions to its open-source vulnerability rewards track to deal with a massive spike in spammy, AI-generated reports.

The program, known as OSS-VRP, was launched in 2022 to pay outside researchers for finding vulnerabilities in critical open-source projects that Google depends on, from Go and Angular to protocol buffers and supply-chain tooling. It quickly became a model for how Big Tech could give back to open source.

That work is now on hold. Google says the vast majority of recent submissions are not real vulnerabilities at all, but low-effort, machine-generated guesses that look convincing on the surface and fall apart under review. Until it can stem the flood, it will not accept new reports in that category, though rewards for Android, Chrome, Cloud, and other core Google products remain active.

The Rise of AI Slop

The problem is not AI itself, but how it is being used. Large language models can now produce a polished vulnerability report in seconds, complete with a severity rating, supposed proof-of-concept, and confident technical explanation.

For bounty hunters chasing payouts, the temptation is obvious: blast dozens or hundreds of AI-written reports and hope one sticks. Many use automated scanners and chatbots to hallucinate buffer overflows, injection flaws, and authentication bypasses in popular GitHub repos without ever validating them.

Security teams call it AI slop, and it is exploding across the ecosystem. Open-source maintainers for projects like curl have publicly complained about receiving a wave of near-identical, bogus security disclosures. HackerOne and Bugcrowd have reported a sharp year-over-year jump in invalid reports since 2023, coinciding with the mainstream adoption of generative AI coding assistants.

Google is simply the biggest name yet to say enough is enough.

Why Triage Is Breaking Down

On paper, an invalid report should be easy to dismiss. In practice, each one still costs real human time.

A triager cannot just assume an AI report is fake. They have to reproduce the environment, check the code path, test the exploit, and document why it fails. When the report is well-formatted and uses correct security jargon, that review can take hours, even if the underlying bug does not exist.

Multiply that by hundreds of junk submissions per week and the math becomes brutal. Google said its open-source security team was spending more time disproving hallucinations than fixing real flaws. That backlog slows patching for actual critical vulnerabilities and burns out the small teams who maintain widely used libraries.

It is also expensive. Even when no bounty is paid, the cost of expert review time adds up fast, turning a program meant to strengthen open source into a drain on it.

The Collateral Damage for Real Hackers

The most frustrated victims are legitimate bug hunters.

Experienced researchers say their valid, deeply researched findings are now stuck in longer queues behind piles of AI spam. Response times are stretching from days to weeks or months. Some report having their detailed work initially dismissed as suspected AI output because reviewers have become jaded.

There is also a trust issue. Programs thrive on the relationship between hackers and vendors. When triagers assume every new submission is likely bot-generated, communication becomes colder and more skeptical. Newcomers who use AI responsibly as an assistant for code analysis risk being lumped in with spammers.

In short, the spammers are not just wasting Google's time, they are devaluing everyone else's labor and threatening to drive skilled researchers away from open-source work toward more lucrative private programs.

What Google's Freeze Signals for the Future

Google's decision is temporary, but the message is permanent: the old bug bounty model was not built for the age of generative AI.

Expect a major overhaul when the program returns. Security insiders anticipate requirements like mandatory working proof-of-concept videos, demonstrated exploitability in a clean environment, reputation scoring for submitters, and possible AI-detection filters or penalties for repeat low-quality reporters. Google has already hinted at stricter validation standards and potential invite-only phases for sensitive projects.

More broadly, the freeze legitimizes what maintainers have been saying for two years. Volume is not value. A bounty program that rewards submissions instead of signal will collapse under its own weight.

Will Others Follow Suit

All eyes are now on Microsoft, Meta, Apple, and GitHub. None have announced a full pause yet, but all are dealing with the same deluge.

Mozilla, the Linux kernel security team, and Python Software Foundation contributors have openly discussed throttling or reforming their intake processes. Commercial platforms like HackerOne have already rolled out new triage fees, submitter ratings, and automated pre-filtering to discourage spam.

Analysts predict a two-tier future. Top-tier, trusted researchers will get faster lanes, higher payouts, and private scopes. Unknown or low-reputation accounts will face much tougher proof requirements, rate limits, and even bans for mass-submitting AI guesses.

Google just fired the starting gun. If AI slop keeps rising, a temporary freeze in open source could soon become standard practice across Big Tech.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
Google Freezes Open Source Bug Bounty After Surge in AI Spam Reports Google Freezes Open Source Bug Bounty After Surge in AI Spam Reports Reviewed by Randeotten on 10/05/2026 05:46:00 AM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.