Analysis
Google has paused its open-source bug bounty program (OSS VRP) until at least the first quarter of 2027, citing what it called "a significant rise in automated submissions, the vast majority of which are not valid," according to BleepingComputer. The freeze, which AndroidHeadlines reports took effect October 1, covers vulnerability reports against Google's open-source projects including Go, Angular and Protocol Buffers -- a program launched in 2022 specifically to pay researchers for privately disclosing real flaws in that code.
AI Slop Overwhelms The Reviewers
The program's reviewers were swamped by reports that were either outright invalid or built around AI-hallucinated vulnerabilities -- plausible-sounding writeups describing bugs that don't actually exist in the code being flagged. Google isn't alone: maintainers across Linux and the curl project have separately described the same flood of automated, low-quality security submissions this year, a predictable risk cybersecurity researchers warned about once anyone could point an LLM at a bug bounty form for a payout.
“That asymmetry is what actually broke the program, not the volume alone -- Google has handled surges in legitimate submissions before.”
The mechanics are straightforward and ugly for the ecosystem: a submission costs the sender almost nothing to generate, while a human reviewer still has to read it closely enough to rule out a real zero-day hiding inside the noise. That asymmetry is what actually broke the program, not the volume alone -- Google has handled surges in legitimate submissions before.
For founders building in application-security and bug-bounty tooling -- HackerOne, Bugcrowd, and a wave of newer AI-triage startups -- this is close to a live product requirement landing in public view: whoever can reliably separate an AI-hallucinated report from a real one, fast and cheap, has a concrete problem Google itself just admitted it can't solve internally with its current process.
That said, pausing the program doesn't make Google's own code less secure -- its internal security teams and paid, invite-only research relationships continue. What goes dark is the open, anyone-can-submit channel smaller researchers and students use to get paid for a first real-world finding, which is the actual cost here, not a new hole in Go or Angular.