Illustration for: Google Freezes Open-Source Bug Bounty Over AI Spam

Google Freezes Open-Source Bug Bounty Over AI Spam

Google paused its open-source bug bounty program until at least Q1 2027 after automated, often AI-hallucinated vulnerability submissions overwhelmed its reviewers.

TC
Early-stage VC & angel · Founder, New York Venture Partners · Value Add Pulse AI Desk
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Google pausing a program it has run since 2022 because reviewers can no longer tell AI-hallucinated vulnerability reports from real ones is a concrete, public admission that AI-generated noise is now an operational cost, not a theoretical risk.

2

Linux and curl maintainers have separately described the same flood this year, meaning this is an ecosystem-wide problem for open-source security, not a Google-specific one.

3

Security-triage and AI-detection startups now have a live, named example of exactly the problem they pitch solving -- proof the demand side is real rather than speculative.

4

What goes dark is the open, anyone-can-submit channel smaller researchers and students use to get paid for a first real finding, which is a talent-pipeline cost more than a security one.

TC

The VC Read · Trace's Take

Trace Cohen

The founders I'd want to meet this week are the ones building AI-vs-AI triage for bug bounty and vulnerability disclosure, because Google just handed them a public, dated proof point that the problem is real and that even a company with Google's own security resources can't absorb it manually. Watch whether HackerOne or Bugcrowd ship a comparable triage layer before a funded startup beats them to it.

Analysis

Google has paused its open-source bug bounty program (OSS VRP) until at least the first quarter of 2027, citing what it called "a significant rise in automated submissions, the vast majority of which are not valid," according to BleepingComputer. The freeze, which AndroidHeadlines reports took effect October 1, covers vulnerability reports against Google's open-source projects including Go, Angular and Protocol Buffers -- a program launched in 2022 specifically to pay researchers for privately disclosing real flaws in that code.

AI Slop Overwhelms The Reviewers

The program's reviewers were swamped by reports that were either outright invalid or built around AI-hallucinated vulnerabilities -- plausible-sounding writeups describing bugs that don't actually exist in the code being flagged. Google isn't alone: maintainers across Linux and the curl project have separately described the same flood of automated, low-quality security submissions this year, a predictable risk cybersecurity researchers warned about once anyone could point an LLM at a bug bounty form for a payout.

“That asymmetry is what actually broke the program, not the volume alone -- Google has handled surges in legitimate submissions before.”

The mechanics are straightforward and ugly for the ecosystem: a submission costs the sender almost nothing to generate, while a human reviewer still has to read it closely enough to rule out a real zero-day hiding inside the noise. That asymmetry is what actually broke the program, not the volume alone -- Google has handled surges in legitimate submissions before.

For founders building in application-security and bug-bounty tooling -- HackerOne, Bugcrowd, and a wave of newer AI-triage startups -- this is close to a live product requirement landing in public view: whoever can reliably separate an AI-hallucinated report from a real one, fast and cheap, has a concrete problem Google itself just admitted it can't solve internally with its current process.

That said, pausing the program doesn't make Google's own code less secure -- its internal security teams and paid, invite-only research relationships continue. What goes dark is the open, anyone-can-submit channel smaller researchers and students use to get paid for a first real-world finding, which is the actual cost here, not a new hole in Go or Angular.

ShareXLinkedInEmail

Key Sources

2 sources

THE WIRE in your inbox— Tech, startup & VC news with Trace's take, a few times a week. Free to subscribe, no spam.