Google pauses open-source bug bounty programme as invalid submissions rise
The company cited a sharp increase in automated reports, most of which it said were invalid, and promised an update in early 2027.

Google paused its Open Source Software Vulnerability Rewards Program from 1 October, citing a significant rise in automated submissions, the vast majority of which it said were invalid.
The programme rewarded researchers who found vulnerabilities in Google’s open-source software. Google said it would provide an update in the first quarter of 2027, but did not give a date for a possible resumption.
Participants were encouraged to consider Google’s other bug bounty programmes during the pause.
TechCrunch reported the pause and cited earlier warnings from cybersecurity experts that AI-generated or automated reports could burden bug bounty programmes. Google’s stated reason referred to automated submissions; it did not say all were AI-generated.
TechCrunch also cited Tom’s Hardware on reports that were invalid or contained hallucinations. Google’s statement, as reported by TechCrunch, said most automated submissions were not valid.
