Google halts its open-source bug bounty program, flooded by AI-generated reports
On 5 October 2026, Google froze product vulnerability submissions to its OSS VRP, drowned under a wave of automated reports that are mostly invalid. Researchers must now route work through the Patch Rewards Program or the Cloud VRP, pending a redesign announced for Q1 2027.
5 October 2026. Google suspends product vulnerability submissions to its OSS VRP (Open Source Software Vulnerability Rewards Program), after being flooded by AI-generated reports. Since 2022. The program rewarded responsible disclosure of flaws in Google-maintained open-source projects — Golang, Angular, Bazel, Protocol Buffers, Fuchsia — as well as in critical third-party dependencies. Why it matters: this is not an isolated incident, but the third retreat of a bounty program in a year under the weight of automated noise, after curl in January and Intel in September.
What is suspended, and what is not
The suspension only affects part of the apparatus. Google stops accepting product vulnerability submissions to the OSS VRP, but keeps processing supply chain reports under the same program, as well as all reports already in flight. Submissions made before 1 October 2026 remain valid. Two doors stay open to researchers: the Patch Rewards Program, which pays up to $15,000 for high-impact fixes, and the Cloud VRP, for flaws in Google Cloud open-source repositories that affect Cloud products.
The stated reason is factual, almost dry: “a significant rise in automated submissions, the vast majority of which are not valid.” The program is a victim of its own success and of the AI turn: code-generation and analysis tools churn out vulnerability reports at scale, and human triage can no longer keep up. Google announces a redesign of the program with an update due in Q1 2027.
A program that paid well, and a lot
The OSS VRP launched in August 2022 with rewards ranging from $100 to $31,337, targeting the flaws with the highest impact on the software supply chain. It sat inside a broader effort: since its first program in 2010, Google has paid out over $81.6 million to thousands of researchers. 2025 alone saw a record $17.1 million paid to more than 700 researchers, a 40% jump from the $12 million of 2024.
The contrast is striking: an ecosystem that has never paid more for security finds itself forced to close a door because the quality of its inputs collapsed. Generous bounties attract both the best researchers and the automata — and the latter drown the former.
curl, Intel, Microsoft: one pressure, three responses
Google is not the first to blink. In January 2026, the maintainer of curl, the command-line tool present in a large share of systems, ended the project’s HackerOne bounty program, overwhelmed by a flood of “AI slop” reports. In mid-September, Intel removed all financial rewards from its Intigriti program, without public explanation, for flaws in its software, firmware, hardware and services.
Among vendors holding the line, the tone has shifted. Microsoft warned back in May 2026 that AI tools now surface far more vulnerabilities, accelerating the pace of discovery across the industry and potentially “raising operational demands.” The September 2026 Patch Tuesday is the illustration: 966 flaws fixed in a single month, a record, including two actively exploited zero-days. Discovery is accelerating; triage remains human.
What it changes for researchers and maintainers
For an independent researcher, suspending the OSS VRP shifts value toward patches rather than reports. The Patch Rewards Program pays for a fix that actually corrects something, not for a description of a flaw: a natural filter against reports generated without understanding the code. For open-source maintainers, the news cuts both ways: less noise to triage on one side, and a source of funding and signal closing on the other, just as pressure on the supply chain has never been higher.
The deeper consequence is economic. Bounty programs run on an equilibrium: the cost of triage must stay below the value of the flaws found. When AI produces plausible-but-false reports at near-zero marginal cost, that equilibrium breaks. Google’s answer — favour verifiable fixes — sketches the industry’s likely direction: pay for code that compiles and corrects, rather than text that describes.
Verdict
If you are a security researcher, stop submitting product vulnerability reports to the OSS VRP and route your work to the Patch Rewards Program for fixes, or the Cloud VRP for flaws affecting Google Cloud products: that is where the value remains, and where automated noise is mechanically filtered out. If you maintain an open-source project, brace for more AI reports to triage as other programs retreat, and demand executable proof of impact rather than descriptions. If you set a bounty budget, favour rewards conditioned on a verified fix: it is the only model that has survived the wave, and it is unlikely that Google’s 2027 redesign turns back the clock.
References
- BleepingComputer — Google halts open-source bug bounty program amid AI spam surge (5 October 2026)
- Google — OSS VRP rules, “product vulnerabilities” (Bug Hunters)
- BleepingComputer — curl ending bug bounty program after flood of AI slop reports (January 2026)
- Risky Biz — Intel ends paid bug bounties (September 2026)
- Microsoft MSRC — A note on Patch Tuesday (May 2026)