Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
Google has hit pause on its Open Source Software Vulnerability Rewards Program. The scheme normally pays researchers for finding security flaws in open-source code. The Google bug bounty freeze took effect on October 1, 2026. Google says new submissions will not be accepted again until early 2027. The reason is not money, and it is not a change of heart about open-source security. It is a flood of bug reports written by AI tools. Most of them describe vulnerabilities that do not actually exist.
Inside the Google bug bounty freeze
Google told researchers the pause was “due to a significant rise in automated submissions, the vast majority of which are not valid.” Engineers and open-source maintainers triage these reports as volunteers. They found themselves buried under AI-written reports. The write-ups looked plausible. Many described bugs that were never in the code at all. Security researchers call this an AI hallucination. A language model describes a flaw with confidence and technical detail. It does this because that is the kind of text it was trained to produce. It has not actually verified the claim against real code.
The Google bug bounty freeze is narrower than headlines suggest. It covers only the Open Source Software VRP. That program rewards reports on critical build tools and widely used libraries. Google’s other reward programs still run as normal. Android, Chrome and its core services all keep accepting reports. Researchers who want to keep earning bounties can use those programs instead.
What counts as an invalid AI submission
Maintainers describe a consistent pattern. A submission arrives with a confident title and a technical-sounding description. Sometimes it includes a proof-of-concept snippet. Then the claim falls apart under review. The code path described does not exist. Or the function behaves differently than claimed. Or the “exploit” needs conditions that can never happen in practice. Large language models can produce this kind of text fast. One submitter can generate dozens of reports in the time it once took to write one.

That volume is the real problem. A valid report still needs a human to read the code and check the claim. When noise drowns out signal, reviewers cannot keep pace. Genuine vulnerabilities risk sitting in a queue behind reports that were never going to check out.
This isn’t just Google’s problem
Google is not alone here. The Internet Bug Bounty program rewards researchers for flaws in widely used open-source infrastructure. It has separately paused some payouts. It is working out how to filter AI-assisted noise from genuine findings. Security publications warned about this exact failure mode as far back as mid-2025. AI writing tools had just become fluent enough to produce convincing, fabricated technical claims at scale. The Google bug bounty freeze shows those warnings were not overblown.
There is an irony here. The same AI boom that Google is racing to build now has to be defended against. Google has touted its own AI-assisted bug-hunting tools in the past. Those systems use large language models to find real vulnerabilities under controlled conditions. Researchers say the difference is oversight. An in-house tool gets its output checked before anyone submits it. An outside researcher can paste a model’s raw output straight into a bounty form.
What happens next for bug hunters
Google has not published a detailed relaunch plan. It has only committed to an update sometime in the first quarter of 2027. Researchers expect new verification steps when the program returns. That could mean requiring a working exploit, not just a description of one. It could mean a vetting layer that flags AI-pattern reports before a human ever sees them.
Real open-source vulnerabilities do not stop appearing just because the reward program paused. Google’s advice is simple. Route anything urgent through its still-open programs, or through the specific project’s own disclosure channel. Do not wait for the freeze to lift. Expect the next concrete update from Google in early 2027. Watch whether other bounty operators, including the Internet Bug Bounty program and large platforms, add their own AI-screening rules before then.
Frequently asked questions
What exactly is the Google bug bounty freeze?
It is a pause on new submissions to Google’s Open Source Software Vulnerability Rewards Program. It began October 1, 2026. Google expects it to last into the first quarter of 2027.
Why did Google pause the program?
A sharp rise in automated, AI-generated submissions overwhelmed the people who review reports. Most of the submissions were invalid. That made it harder to find genuine vulnerabilities in the backlog.
Does this affect Android or Chrome bug bounties?
No. Google’s other reward programs, including Android and Chrome, remain open. They are accepting reports as usual.
Can researchers still report open-source bugs they find?
Yes, through the individual project’s own disclosure channel. They will not currently be eligible for a reward until the paused program reopens.
Is Google the only company dealing with AI-generated bug reports?
No. The Internet Bug Bounty program has separately paused some payouts over a similar flood of AI-assisted submissions. Researchers say the issue is spreading across the industry.
When will the program reopen?
Google has only said to expect an update in the first quarter of 2027. It has not committed to a specific relaunch date.
Sources
- TechCrunch — Google froze its open source bug bounty program due to a “significant rise” in AI submissions. techcrunch.com
- InfoWorld — Stop using AI to submit bug reports, says Google. infoworld.com
For more on how AI systems are colliding with security practice, see our coverage of the rogue AI agents flagged on Hugging Face and government sites and the FTC’s probe into AI agents.
Verification your users actually receive.
Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

