Google suspends open source bug bounty program following ‘significant increase’ in AI submissions
- Google stopped sending OSS bug bounties after a surge of AI-generated invalid reports
- AI drives vulnerability discovery, but often produces erroneous, incomplete, or hallucinatory findings.
- The growing AI-driven bounty spam has also overwhelmed curl maintainers and Linux security reviewers.
Google has revealed that it is pausing one of its bug bounty programs and that it is all the fault of AI.
The company said its Open Source Software Vulnerability Reward Program (OSS VRP) is being inundated with false and irrelevant submissions to the point that it is simply unmanageable.
As a result, the company will stop accepting all submissions until the end of the year, taking the time to re-evaluate the process and propose new solutions.
Latest videos ofTechnologyRadar
Bug hunting in the age of AI
Generative Artificial Intelligence is empowering defenders, discovering vulnerabilities at machine speed, making software better and more resilient against exploits and zero-day vulnerabilities.
Some cutting-edge models, including the famous Mythos and GPT-5.6-Cyber, have allowed companies to discover hundreds of times more vulnerabilities in less time than ever before.
The best example is Microsoft’s Patch Tuesday. In March 2026, the company fixed 79 bugs in its products, and in April (when it started using Mythos), almost double that number (167). From that day on, the number of bugs patched grew significantly month after month: 200 in June, 400 in August, and 966 in September. In just half a year, Microsoft began fixing more than ten times as many bugs.
However, machines still cannot be trusted to discover and fix vulnerabilities on their own. In early August, security researchers at 1Passwords Off-by-1 Labs set out to see how good AI was at discovering and fixing flaws and found that half (49.3%) of patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original problem but changed the behavior of the app, while 2.3% introduced new security issues. Interestingly, 2.2% failed to fix the vulnerability and at the same time introduced additional exploitation paths.
Even among the patches that could be considered (26% of clean ones and 20.1% of those that changed application behavior), more than a third were fragile and did not fully address the underlying problem. 1Password concluded that lack of context was the number one challenge and found that when given the right background information, AI could produce significantly better results.
Despite not being able to provide its AI with broader context, many security researchers still use it to discover vulnerabilities. Simple prompts, very little analysis, and even less human oversight result in incorrect, unsubstantiated, and sometimes downright mind-blowing “discoveries.” As a result, Google is (temporarily) moving away from introducing rewards:
“We are temporarily no longer accepting vulnerability submissions for OSS VRP products. This does not affect OSS VRP supply chain reports or any pending reports. Alternatively, we encourage you to find the impact in our other VRP programs and submit them there, or follow the Patch Rewards program,” Google said in a short tweet, posted on October 1, 2026.
“Why is this happening? This pause is due to a significant increase in automated submissions, the vast majority of which are invalid. We will continue to reformat and work on this aspect of the OSS VRP and will commit to providing an update in the first quarter of 2027.”
HackerOne and Linus Torvalds
Google is not the first company whose bug bounty program was drowned by AI. In late January 2026, the developers of curl, the open source command-line tool and software library, announced the removal of their HackerOne bug bounty program because it was inundated with fake issues and vulnerabilities.
In a notice posted on GitHub, it was said that the program will end at the end of January 2026.
“Until the end of January 2026 there was a curl bug bounty. It no longer exists,” the document reads. “The curl project no longer offers bounties for reported bugs or vulnerabilities. We also do not help security researchers obtain such bounties for curl issues from other sources.”
A few months later, in May, the head of the Linux security mailing list, Linus Torvalds, said it was “almost completely unmanageable” because researchers were using AI to flood it with useless reports.
“The continuing deluge of AI reports has basically made the security list almost completely unmanageable, with enormous duplication due to different people finding the same things with the same tools,” he said. “People spend all their time forwarding things to the right people or saying ‘that was fixed a week or a month ago’ and pointing out the public discussion.”
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment