IA · 5 October 2026 · 3 min read
Flooded by AI Submissions, Google Freezes Its Open Source Bug Bounty Program
In brief: Google has indefinitely suspended its Open Source Software Vulnerability Rewards Program (OSS VRP) after a dramatic increase in automated, AI-generated reports overwhelmed engineers. With the vast majority of submissions turning out to be hallucinations or invalid flaws, the triage process became unsustainable. The freeze will last at least until the first quarter of 2027, highlighting a growing crisis in open source vulnerability management in the age of generative AI.
by Team Mocchi's
For years, bug bounty programs have served as one of the most reliable cornerstones of modern cybersecurity: offering financial payouts to independent researchers who uncover flaws before malicious actors can exploit them. However, the rise of advanced language models and automated agents has upended the fragile balance between researchers and reviewers. The latest casualty is one of the industry's benchmark initiatives: Google has frozen its Open Source Software Vulnerability Rewards Program (OSS VRP), halting all new submissions effective retroactively from October 1.
The suspension will remain in place until at least the first quarter of 2027, when Mountain View plans to share an update on the program's restructuring. As reported by TechCrunch, the move was triggered by an unsustainable surge in automated submissions, the vast majority of which proved to be entirely invalid or polluted by AI hallucinations.
Drowning in hallucinated vulnerability reports
The underlying mechanism driving this crisis is as straightforward as it is disruptive. Script-driven LLM pipelines now routinely scan public repositories, identify speculative vulnerability patterns, and generate polished, multi-page security reports within seconds—replete with impact assessments and theoretical proofs of concept. On the surface, these submissions look impeccably professional, adopting standard industry terminology and strictly adhering to disclosure guidelines.
In practice, however, Google engineers and open source maintainers found themselves buried under what cybersecurity circles now term "AI slop": theoretical edge cases with zero real-world impact, broken exploit scripts, and entirely fabricated bugs hallucinated by language models. The marginal cost of generating these tickets has dropped to near zero: submitting automated scrapings across hundreds of repositories costs virtually nothing, while a single lucky payout justifies the effort. Conversely, triaging and disproving a hallucinated flaw still demands hours of rigorous human investigation.
The collapse of open source triage
Google's OSS VRP specifically protects open source projects developed or maintained by the company—foundational codebases that support much of the modern web's infrastructure. While Google’s standard commercial bug bounty programs remain open, open source projects represent the most vulnerable link in the chain. Maintainers are frequently small teams or volunteers already working under severe time and resource constraints.
When hundreds of hollow, machine-generated reports flood their queues, the entire triage process grinds to a halt. Reviewers spend nearly all their bandwidth debunking algorithmic fantasies, creating a severe operational risk: genuine, critical security vulnerabilities could easily get lost in the noise. Shutting down the program temporarily is an admission that human triage capacity has hit a hard ceiling.
Rethinking security incentives in the agentic era
Google's predicament is far from unique, pointing instead to a structural crisis across software development. Vulnerability reward models were designed on the assumption that writing a credible report required specialized, scarce human expertise—a built-in barrier that effectively kept spam at bay. Now that synthetic code and text generation allow anyone to unleash thousands of submissions with a few lines of code, that economic framework is breaking down.
To safely revive the initiative in 2027, Google will almost certainly need to enforce strict gating mechanisms: robust researcher reputation systems, penalties for repeatedly submitting automated false positives, or mandatory, reproducible sandbox verification before a report is ever routed to a human engineer. Without a comprehensive overhaul of these incentives, open ecosystems will increasingly be forced to shut their doors to external input simply to survive.
Mocchi's take
This pause exposes a fundamental paradox of the current AI boom: collapsing the cost of generating complex artifacts merely shifts the entire cognitive and economic burden onto verification. For businesses and engineering teams adopting open source software, the lesson is clear: automated LLM vulnerability scanners cannot be treated as silver bullets without strict, deterministic validation pipelines. Chasing automated alert volume without filtering for signal will inevitably paralyze the very technical teams it is supposed to empower.