Story
October 5, 2026
AI Slop Forces Google to Freeze Its Open-Source Bug Bounty
Google has suspended rewards for vulnerabilities in its open-source software after automated AI-generated reports, most of them invalid, overwhelmed reviewers. The company says it will provide an update in the first quarter of 2027.
Google’s Open Source Software Vulnerability Rewards Program, which pays researchers for flaws found across the company’s open-source ecosystem, was paused on October 1 after a flood of AI-generated reports bogged down its reviewers.1
The company’s explanation was blunt: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”1 Engineers and open-source maintainers were reportedly inundated with submissions that were either invalid or riddled with AI hallucinations — a workload that turns a vulnerability-rewards program into a triage operation.1
The freeze will last until at least next year, with Google promising an update in the first quarter of 2027. In the meantime, it has directed would-be researchers toward its other bug-bounty programs.1
The episode lands after earlier warnings from cybersecurity specialists that AI-generated “slop” could damage bug-bounty systems by burying legitimate reports beneath automated junk.1 Google’s decision suggests that risk is no longer theoretical: the volume of low-quality submissions has become disruptive enough to halt an entire open-source rewards channel.
The pressure is not confined to Google. Linux has faced a similar wave of problematic AI-driven reports, underscoring a broader conflict for open-source projects: automation may expand the pool of people filing bugs, but it can also consume the scarce human attention needed to verify them.2
For legitimate security researchers, the pause removes one route to compensation. For maintainers, it is an admission that the current reporting pipeline cannot distinguish signal from synthetic noise quickly enough.2