Blaming a “significant rise” in AI submissions, Google has paused its open source bug bounty program until next year. Last year, TechCrunch reported that cybersecurity experts were warning of that AI slop posed a serious risk to bug bounty programs . Looks like that’s the issue confronting Google’s Open Source Software Vulnerability Rewards Program, where researchers were rewarded for finding vulnerabilities in the company’s open source software.
In posts on X and the program website , Google said the bug bounty program was paused as of October 1, with a promise to provide “an update” in the first quarter of 2027. According to Tom’s Hardware , Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said. In the meantime, participants are encouraged to consider Google’s other bug bounty programs. Get 50% off a second pass The Disrupt experience is meant to be shared.
Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem. Every weekday and Sunday, you can get the best of TechCrunch’s coverage. TechCrunch Mobility is your destination for transportation news and insight. Startups are the core of TechCrunch, so get our best coverage delivered weekly. Provides movers and shakers with the info they need to start their day. By submitting your email, you agree to our Terms and Privacy Notice .
