i
News
News · 2026-10-04

Google pauses open-source bug rewards after automated submission surge

@neuronium_ai @neuronium_ai

Google has suspended its Open Source Software Vulnerability Rewards Program after a surge in automated submissions overwhelmed review. The program paid researchers for finding vulnerabilities in Google’s open-source software; it has been paused since October 1. Google says it will share an update in the first quarter of 2027, leaving participants without a date for its return.

Cover: Google pauses open-source bug rewards after automated submission surge

Source: techcrunch.com

A review bottleneck

Google attributed the suspension to a sharp rise in automated reports, the vast majority of which were invalid. According to Tom’s Hardware, Google engineers and open-source maintainers received so many invalid and hallucinated submissions that they could not keep up with reviewing them.

The pressure was not unique to Google. Last year, TechCrunch reported that cybersecurity specialists were warning that low-quality AI-generated reports could burden vulnerability reward programs.

While the program is paused, Google is directing participants to consider its other vulnerability reward programs.

The missing measure

The announcement offers no figure for how many submissions arrived, or how much of the increase came from AI. I think the key issue is not simply that automated reports are invalid, but that reviewers have to spend time establishing that they are. The pause shows how quickly a reward program can become a screening operation when submissions scale faster than review.

Google has promised an update, not a restart date. Until then, the question is whether its next update will explain how the program can reopen without restoring the same review bottleneck.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X