Google Bug Hunters platform

Google has frozen new submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026 (UTC), after a flood of AI-generated vulnerability reports overwhelmed its review team. The program won't resume accepting product vulnerability reports until at least Q1 2027.

What happened

Google's OSS VRP, launched in 2017, pays security researchers for responsibly disclosing vulnerabilities in open-source software that Google maintains or depends on. It's been a cornerstone of the company's security strategy — since 2010, Google's various bug bounty programs have paid out over $59 million to researchers across 68 countries.

That pipeline is now clogged. According to Google, the volume of submissions surged to unmanageable levels, and the vast majority of the new influx consists of low-quality or entirely fabricated reports generated by AI tools. Human reviewers were spending most of their time triaging garbage instead of validating real vulnerabilities.

The freeze applies specifically to product vulnerability reports. Supply chain vulnerability rewards — the category covering things like malicious package uploads and dependency confusion attacks — remains active, because those reports tend to come from established researchers and are harder to fake at scale.

The AI slop problem

This isn't a Google-specific headache. Open-source maintainers across the ecosystem have been complaining for months about AI-generated pull requests, issue reports, and vulnerability disclosures that range from subtly wrong to completely hallucinated. The pattern is consistent: an LLM scans a codebase, flags something that looks like a vulnerability, and generates a polished-looking report with reproduction steps that don't actually work.

What makes the bug bounty context particularly toxic is the financial incentive. A valid vulnerability report can pay anywhere from a few hundred dollars to tens of thousands. That creates a direct economic motive to flood the system with AI-generated submissions in the hope that a small percentage slip through and get paid. It's the security-research equivalent of clickfarms.

Google isn't the first to hit this wall. Several smaller bug bounty platforms have already introduced AI-detection filters, submission rate limits, and reputation scoring to throttle automated reporters. Google's decision to pause the entire program rather than patch it with filters suggests the volume was high enough that incremental fixes weren't working.

Why it matters

The immediate impact is that a major channel for finding and fixing vulnerabilities in widely-used open-source software is now closed for at least three months. That's not a small window — in Q4 2025, the OSS VRP processed reports that led to fixes in projects including Kubernetes, TensorFlow, and Angular. With the program frozen, those vulnerabilities either go undiscovered or get reported through slower, less structured channels.

The deeper issue is what this says about the AI-generated content flood. We've already seen AI slop overwhelm Amazon product reviews, Stack Overflow, and academic publishing. Now it's hitting the security infrastructure that protects the software supply chain. The economics are brutal: generating an AI vulnerability report costs pennies and takes seconds; reviewing it costs a skilled engineer's time and takes minutes to hours. The asymmetry means any program with a financial reward is inherently vulnerable to this kind of attack.

Google's pause is essentially a circuit breaker. The real question is what the program looks like when it comes back in Q1 2027. Options include mandatory human verification of reproduction steps, higher reputation thresholds for new submitters, per-account submission limits, and possibly using AI detectors to triage incoming reports — fighting AI with AI, in other words. None of those are perfect, and all of them risk excluding legitimate independent researchers who don't have established reputations.

What to watch

The bug bounty model has worked well for 16 years because it aligned incentives: researchers got paid, companies got safer software. AI breaks that alignment by making the cost of submitting a report approach zero while the cost of reviewing one stays constant. Google's freeze is the first major crack in a model that the entire tech industry depends on.