Google has temporarily frozen its reward program for vulnerabilities in open-source software. The company said the suspension took effect on October 1, 2026, and was driven by a significant rise in reports created with the help of artificial intelligence tools. According to TechCrunch's October 4 report, Google stated that the vast majority of automatically submitted reports are invalid.

The company did not give an exact date for resuming the program, but promised an update on the situation in the first quarter of 2027 — meaning the pause that began on October 1 will last at least until early 2027. In the meantime, participants were advised to look at Google's other bug bounty programs.

What caused it

Finding and reporting vulnerabilities in the open-source ecosystem is an important part of security work. Google's OSS VRP program existed for exactly this purpose: researchers found flaws in open-source components and earned rewards for reporting them to the company. Reports first went through triage: if a vulnerability was confirmed, the researcher received a reward based on its severity, and the results helped make the open-source ecosystem more secure.

But the situation changed with the popularization of AI code-analysis and report-writing tools. Now anyone can automatically generate dozens of reports in a few minutes and submit them to the reward system. According to Google, the "vast majority" of such reports turned out to be invalid.

Google said the program was suspended due to a "significant rise in submissions created with the help of artificial intelligence." — TechCrunch, October 4, 2026

This problem became clearly visible within Google's OSS VRP program: with the popularization of AI tools, anyone can automatically generate dozens of reports in a few minutes and send them to the reward system. As report volume grew, separating genuine vulnerabilities became harder — every incoming report, even one generated automatically, must be read and analyzed by a human. Google engineers and open-source project maintainers found themselves buried under this flood, so the company decided to temporarily stop accepting new reports.

Engineers and maintainers under excessive load

According to TechCrunch, citing Tom's Hardware, Google engineers and open-source project maintainers were inundated with a flood of invalid or hallucination-filled reports. Reviewing each incoming report takes human resources — even if a report was generated automatically, rejecting it requires reading and analyzing it.

As a result, the program began working against its own purpose: instead of finding real vulnerabilities, the team's time was mostly spent triaging useless reports. From the program operator's perspective, pausing in such a situation is a logical step: halting the intake of new reports until the system is cleaned up also protects genuine researchers.

It is worth noting that Google explained the problem not only in terms of quantity, but also quality. There were not just too many reports — they turned out to be unreliable. When analyzing code, AI models can "find" vulnerabilities that do not exist, and such a report wastes the reviewer's time.

Next steps and recommendations for participants

Google did not announce a full shutdown of the program — this is specifically a temporary suspension. The company said it would provide an official update on the situation in the first quarter of 2027. This timeline gives Google time to review the report triage process, strengthen mechanisms for detecting automated reports, and adapt the program to new conditions.

In the meantime, researchers wishing to participate in reward programs were advised to look at Google's other bug bounty programs. These programs focus mainly on vulnerabilities in Google's own products and services, and they are reportedly continuing to operate. For participants researching products in the Google ecosystem rather than open-source components, these programs remain an available option.

This case also raises a broader question: while AI tools can accelerate security research, how will reward systems defend themselves against automated spam? The suspension decision does not affect open-source projects themselves — the projects continue to develop as usual; this concerns only Google's reward program in this area. Researchers can continue reporting found vulnerabilities directly to project teams or to other reward platforms. If no answer is found, other large programs may be forced to take similar measures. For now, though, researchers who were expecting Google rewards for flaws in open-source projects will have to wait at least until early 2027.

Read more: Full TechCrunch article