Google froze its open source bug bounty program due to a 'significant rise' in AI submissions
AI slop seems to be overwhelming bug bounty programs.

TL;DR
- Google paused its Open Source Software Vulnerability Rewards Program on October 1.
- The pause is due to a significant rise in automated submissions, mostly invalid.
- AI-generated submissions have overwhelmed Google engineers and open source maintainers.
- The program is expected to resume with an update in the first quarter of 2027.
- Participants are encouraged to explore Google's other bug bounty programs.