The open-source Google bug bounty program is on hold: Google stopped accepting product vulnerability reports to its Open Source Software Vulnerability Rewards Program (OSS VRP) as of Oct. 1, 2026, citing “a significant rise in automated submissions, the vast majority of which are not valid,” as TechCrunch and BleepingComputer reported.
What the Google bug bounty pause covers
The OSS VRP pays researchers who find security flaws in open-source projects Google maintains, including Go, Angular, Bazel, Protocol Buffers and Fuchsia, plus critical third-party dependencies. BleepingComputer said Google launched it in August 2022 with rewards from $100 to $31,337.
The pause applies only to new product vulnerability submissions. Google said supply-chain reports and any reports already in the queue are not affected, and product vulnerabilities filed before Oct. 1 will still be handled. The company promised an update in the first quarter of 2027 on its Bug Hunters site.
Why AI slop is swamping bug bounties
TechCrunch, citing Tom’s Hardware, reported that Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinations. Each bogus finding still takes skilled people time to reproduce and reject, which drains the same teams that fix real bugs.
Google is not alone. BleepingComputer noted that the curl project ended its HackerOne bug bounty in January after a flood of AI-generated reports, and that Intel removed financial rewards from its Intigriti program in mid-September without explaining why. Microsoft warned in May that AI tools are speeding up vulnerability discovery across the industry.
Where security researchers can still get paid
Google is steering researchers to its other reward programs. The Patch Rewards Program still pays up to $15,000 for high-impact fixes to open-source software, and flaws in Google Cloud open-source repositories that affect Cloud products can go to the Cloud VRP, BleepingComputer reported. Since launching its first VRP in 2010, Google has paid researchers more than $81.6 million, including a record $17.1 million to more than 700 researchers in 2025, according to BleepingComputer.
The bigger AI security picture
The pause shows the two sides of AI in security. The same tools that flood triage queues can also help defenders, as in our coverage of Gemini 4 Argon rolling out to cyber defenders. And as AI agents grow more capable, labs are also wrestling with containment, from OpenAI pausing training after an agent sandbox escape to the Nvidia open agent safety platform. For bug hunters, the lesson is simple: verified, reproducible reports still matter more than volume.
Sources: TechCrunch; BleepingComputer; Google Bug Hunters.