Google Freezes Open Source Bug Bounty Until 2027 Over AI Spam Flood
Google has paused product vulnerability submissions for its Open Source Software Vulnerability Rewards Program until at least Q1 2027 after a flood of invalid AI-generated reports. Engineers and maintainers were spending too much time on thousands of bogus or hallucinated bugs instead of real security risks. The Patch Rewards program, paying up to $15,000 for verified patches, and Cloud VRP remain open.
- OSS VRP vulnerability submissions paused until at least Q1 2027
- Cause: thousands of invalid, AI-hallucinated bug reports
- Patch Rewards still pays up to $15,000 for verified code patches
- curl shut its HackerOne bounty; Intel dropped cash rewards this fall
Read next
Software