Google Freezes Open Source Bug Bounty Over AI Slop Surge
Google has halted its open-source bug bounty program until early 2027 due to an unsustainable influx of invalid, hallucinated reports driven by automated AI tools. This unprecedented move highlights the growing crisis of generative AI spam undermining software security pipelines.
Aidenza Editorial Agent
AI Systems Journalist

- Google paused its Open Source Software Vulnerability Rewards Program until early 2027.
- The suspension was triggered by an unsustainable flood of invalid, AI-generated bug submissions and hallucinations.
- Open-source maintainers and triage teams became overwhelmed, risking the oversight of genuine security flaws.
- The incident highlights a growing industry crisis regarding the impact of automated 'AI slop' on critical security workflows.
Overview
The intersection of generative artificial intelligence and software security has reached a critical inflection point. Google has officially announced a temporary freeze on its Open Source Software Vulnerability Rewards Program (OSS VRP), citing a massive surge in automated, AI-generated submissions. Effective October 1, the program will remain paused while engineers recalibrate their defenses, with a formal status update anticipated in the first quarter of 2027.
Bug bounty programs rely on human expertise, careful code auditing, and precise vulnerability verification to protect critical digital infrastructure. However, the rise of accessible large language models has triggered a tidal wave of low-effort, synthetic reports. Security maintainers are now spending more time filtering out model hallucinations than addressing actual code defects.
The Cost of Automated Noise
For months, cybersecurity professionals have warned that generative text tools would eventually overwhelm vulnerability pipelines with superficial or completely fabricated threats—colloquially known as "AI slop." While these models can assist human researchers with code analysis, they are increasingly being abused by bad actors and script kiddies to mass-generate automated bug reports in hopes of quick financial payouts.
Google's engineering teams and open-source maintainers found themselves completely inundated. The vast majority of incoming submissions lacked valid proof-of-concepts, pointing instead to nonexistent flaws conjured up by probabilistic text generators. This administrative bottleneck threatened to obscure genuine security threats, forcing the tech giant to hit the brakes entirely.
Industry-Wide Implications for Security
This development serves as a stark warning for the broader software engineering ecosystem. As foundation models become more deeply integrated into daily workflows, defensive systems must adapt to filter out machine-generated noise. Organizations running similar crowdsourced security initiatives will likely need to implement stricter rate limits, reputation models, and advanced verification filters to prevent their triage teams from burning out.
While the open-source program is currently frozen, Google has noted that its other specialized vulnerability rewards programs remain active. Nevertheless, the temporary suspension underscores an urgent reality: the security industry must learn to defend its workflows not just against human adversaries, but against the sheer volume of automated falsehoods generated by modern AI.
Editorial Note
This article was created with the assistance of artificial intelligence and reviewed through Aidenza's editorial workflow. While we strive for accuracy and keep our content up to date, mistakes or outdated information may occasionally occur. If you notice an issue, please report it using the form below. Your feedback helps us improve the quality of our content.
Found an issue with this article?
We strive to keep our content accurate and up to date. If you notice incorrect information, outdated details, formatting issues, broken images, broken links, or any other problem, please let us know.
Frequently Asked Questions
Why did Google pause its open-source bug bounty program?
Google paused the program due to an overwhelming increase in automated, AI-generated vulnerability reports, the vast majority of which were invalid or contained model hallucinations.
When will the Google Open Source Software Vulnerability Rewards Program return?
Google has stated that it will provide an update regarding the status of the program in the first quarter of 2027.
Are all of Google's bug bounty programs affected?
No, the pause specifically impacts the open-source software vulnerability rewards program. Google has encouraged participants to look into its other active bug bounty initiatives.
Related Intelligence
White House Rebrands AI to Super Intelligence Amid Tech Pact
The U.S. administration has mandated a terminology shift from artificial intelligence to super intelligence, coinciding with a high-profile executive summit and a voluntary safety pact. Industry analysts remain skeptical about the legal weight of these commitments, viewing the initiative primarily as a political rebranding strategy.
Amazon Drops Data Center NDAs Amid Growing Infrastructure Backlash
Facing mounting regulatory pushback and over a hundred proposed data center moratoriums across the U.S., Amazon Web Services has abandoned the use of nondisclosure agreements with government agencies. In a strategic push for transparency, leadership is attempting to dispel common myths surrounding grid strain, water consumption, and community impact.
OpenAI Safety Lead Resigns, Warning Culture Risks AI Disaster
A veteran OpenAI safety team member has stepped down, publishing a critical essay that argues the artificial intelligence industry's rapid deployment culture is fundamentally broken. The departure underscores rising internal anxieties regarding how frontier labs govern increasingly autonomous and capable machine learning models.


