Google Halts Bug Bounty Program
Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year.
Cybersecurity experts previously warned that AI-generated submissions, often referred to as 'AI slop,' could pose a serious risk to bug bounty programs. This appears to be the challenge facing Google’s Open Source Software Vulnerability Rewards Program, which compensates researchers for identifying vulnerabilities in the company’s open source software.
Google announced on its program website and social media that the bug bounty program was paused starting October 1, with an update promised in the first quarter of 2027. Reports indicate that Google engineers and open source maintainers were overwhelmed by a high volume of invalid or hallucinated submissions.
The company stated that the pause is a direct result of 'a significant rise in automated submissions, the vast majority of which are not valid.'
Participants are encouraged to explore Google’s other existing bug bounty programs during this interim period.




