Google paid bug hunters to find open-source flaws, then AI flooded the queue with made-up bugs

Google paid bug hunters to find open-source flaws, then AI flooded the queue with made-up bugs

By Jennifer Green
Publication Date: 2026-10-08 04:35:00

A flood of AI-assisted bug filings pushed Google to halt a rewards program that pays for flaws found in its open-source software. Rather than keep human reviewers buried in reports the company considers unreliable or made up, it paused the effort.

Here’s what to know

According to TechSpot, Google stopped taking product vulnerability submissions through its Open Source Software Vulnerability Rewards Program. Google tied the move to a surge in automated reports that reviewers could not keep up with.

Google launched the OSS VRP to pay security researchers who find vulnerabilities in its open-source projects, including Go, Angular, and Fuchsia. Useful submissions can reward researchers and help Google close security gaps.

Google’s Bug Hunters team said it will no longer accept those submissions. Updated program rules also state that reports filed after Oct. 1 would be rejected, while submissions filed before Oct. 1 were under review.

More background