Google pauses open source bug bounty submissions as AI-generated reports pile up
In brief
- Google stopped accepting new product submissions to its OSS VRP starting October 1, 2026.
- Google cited a surge of low-quality, AI-generated reports, many containing hallucinations.
- The pause is partial, not a full shutdown; researchers are pointed to Patch Rewards.
- A formal update on submission reforms is expected from Google in Q1 2027.
Why Google hit pause
Google tied the suspension to a surge of low-quality, automated reports produced with AI tools, Crypto Briefing reported. Those reports landed on security engineers and on the maintainers of open source projects. According to Google, many of the submissions contained hallucinations. Others described issues with negligible real-world impact, and most of the submissions in the surge turned out to be invalid.
That's a real cost. Bug bounty programs rely on manual triage (a human reads each report, tries to reproduce the issue and decides whether it's an actual vulnerability), so every bogus submission eats reviewer time. Many open source projects are maintained by small teams or volunteers, and Google cited the burden on those maintainers in explaining the pause.
Where researchers go now
The OSS VRP isn't being shut down. Google is pointing researchers toward its other active reward programs while the pause is in place, specifically its Patch Rewards program, according to Crypto Briefing. Researchers who find real flaws in open source products will need to use those other Google VRPs or Patch Rewards for now.
Google said it plans to revise how submissions work.
A formal update on those reforms is expected in Q1 2027.
Not the first adjustment
This isn't Google's first move on the problem. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports, raising the evidence bar for researchers, and it also changed its reward programs for Android and Chrome during 2026. Crypto Briefing called the OSS VRP suspension the most aggressive step so far.
Google isn't alone, either. The Internet Bug Bounty program, Intel and Linux kernel maintainers have also dealt with rising volumes of questionable reports driven by generative AI, Crypto Briefing reported. Some of those programs have responded with pauses and adjustments of their own.
Frequently asked questions
Is Google shutting down its Open Source Software Vulnerability Reward Program?
No. Google paused new product vulnerability submissions to the OSS VRP starting October 1, 2026, but the pause isn't a full shutdown of the program, according to Crypto Briefing.
Why did Google pause OSS VRP submissions?
Google linked the pause to a surge of low-quality, automated reports produced with AI tools. Many contained hallucinations, others described issues with negligible real-world impact, and most turned out to be invalid. Google also cited the burden on open source maintainers, many of whom are small teams or volunteers.
Where can researchers report open source flaws during the pause?
Google is pointing researchers toward its other active reward programs, specifically its Patch Rewards program. Google expects to give a formal update on how submissions will work in Q1 2027.


