Google froze its open source bug bounty program on October 1, citing a significant rise in AI-generated submissions that overwhelmed its security team. The company said the pause was necessary to address a surge in automated reports that were largely invalid or contained hallucinations.
According to Tom’s Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. The company said the pause was due to a significant rise in automated submissions, the vast majority of which are not valid.
Participants are encouraged to consider Google’s other bug bounty programs while the open source initiative is paused. Google promised to provide an update in the first quarter of 2027.
"This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said. The statement highlights the challenge of distinguishing between legitimate security reports and AI-generated false positives.
The announcement follows warnings from cybersecurity experts last year about the risks posed by AI-generated submissions to bug bounty programs. Google’s decision reflects growing concerns about the reliability of AI in security testing.
Google did not say when the program will resume, and it raised concerns about the impact of AI on the integrity of security testing. The company said it would provide more details in early 2027.
Source: techcrunch