Read as article
Google Pauses Open-Source Bug Bounty Amid AI Spam
By @sharedot · · 8 pages
- Programming
- Open Source
- Bug Bounty
- AI Spam
Google paused vulnerability submissions to its OSS bug bounty program after a flood of invalid AI-generated reports overwhelmed engineers.
What Happened
Google has paused product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) after a flood of invalid, AI-generated reports overwhelmed security engineers and repository maintainers. The company announced the operational freeze in a post on X, took effect immediately on October 1, and directed security researchers toward its other active reward initiatives while it restructures the submission framework.
Why It's a Reversal
A bug bounty being shut down by too many reports is an inversion of its purpose: reward programs exist to attract more vulnerability disclosures, not fewer. Google stated plainly that the pause is due to a significant rise in automated submissions, the vast majority of which are not valid. Per the Times of India, Intel also recently froze its bug bounty program, which offered payouts reaching $100,000 per flaw; Intel did not cite synthetic submissions as the official cause, but industry analysts widely attribute the shutdown to identical AI spam bottlenecks.
The Evidence
The Times of India reports that Linux maintainers earlier described being completely flooded by bogus CVE filings after automated AI hunters drove recorded vulnerabilities to a record high of 2,000 per release, an influx that forced the Linux project to drop support for older network drivers. It's FOSS adds that maintainers are already drowning in AI slop pull requests and bug reports, giving the pattern an independent corroboration from a second publisher.
What Stays Open
The suspension took effect immediately on October 1, but Google outlined specific exceptions to avoid shutting down critical disclosure channels. The pause does not affect valid product vulnerability filings logged before October 1, and the freeze applies specifically to product vulnerability reports; supply chain disclosures submitted under the OSS VRP remain open. Product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.
The Stakes for Maintainers
The pause lands on a community already under financial and logistical strain. It's FOSS reports that DigitalOcean is quietly sunsetting its Open Source Credits program, citing an email Node.js maintainers received; no new applications, renewals, extensions, or additional credit requests will be approved, and the opensource@digitalocean.com inbox will no longer be monitored. Maintainers losing both hosting support and a reward channel face harder infrastructure bills while filtering AI slop from their queues.
What Comes Next
Google stated it will continue to reformat and work on the OSS VRP and committed to giving a progress update in the first quarter of 2027. Until then, the company encourages researchers to find impact across its other VRP programs or pursue the Patch Rewards Program. Meanwhile, tooling meant to reduce maintainer load keeps arriving — InfoQ reports AWS open-sourced Pizza Bot, an inbox-style application for running AI agents in the background with human approval gates.
Sources
More on Programming
- England Hit Seven in Rijeka, Croatia's First Home Loss There
- Ascend Supernode Pushed to Hardware Limits as Huang Concedes China
- Cloudflare Basin Goes GA, Taking Aim at Snowflake
- DeepSeek Open-Sources TileLang Software for Huawei Ascend Chips
- Rust Nears Rails: First EN 50716 Railway Certification Package