Skip to main content
Back to News
news/AI Safety

Google Pauses Open-Source Bug Bounty Over AI Slop Flood

Google paused its open-source bug bounty after a flood of AI-generated reports, leaving maintainers drowning in invalid, hallucinated submissions.

Stefan Trbojevic

Stefan Trbojevic

5 October 20262 min read
LinkedIn
Abstract illustration of data packets flowing through a narrow gateway filter

The takeaway

Automated AI findings still need human verification before they reach a shared queue. Google's pause shows how much triage cost unvalidated agent output adds, and it thins out the paid disclosure channel for open-source security.

Why it matters for builders

Teams running AI agents that scan code or file security reports should add a human verification gate: unvalidated agent output is a triage cost shifted onto someone else. Google's pause also removes a paid disclosure channel for open-source vulnerabilities, so maintainers of projects you depend on are now less resourced to hear about real flaws.

Google Pauses Open-Source Bug Bounty Over AI Slop Flood

Google has stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), the bug bounty that pays researchers for finding flaws in the company's public code, including projects like Go, Angular, and Protocol Buffers. The pause took effect October 1 and runs until at least a promised update in the first quarter of 2027.

The reason, in Google's own words, is a "significant rise in automated submissions, the vast majority of which are not valid."

What exactly changed

The OSS VRP rules page now states plainly: "As of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP." Reports filed before that date are unaffected. Supply-chain reports, which require demonstrating a concrete path to tamper with source code or release artifacts, remain open. For some Google Cloud repositories, product bugs may still be routed through the separate Cloud VRP.

According to Tom's Hardware, Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinated findings. In many cases, triaging a single report cost more time than it was worth.

Diagram showing many generated report nodes crowding a filter while only a few pass through as validated findings

Why AI slop broke bug bounties

Bug bounties run on a simple trade: researchers spend expensive manual effort, and companies pay for the few findings that actually matter. Large language models collapsed the cost of producing a fluent, confident, plausible-looking report to almost zero. The result is a flood of submissions that sound serious but are wrong, and every one of them still needs a human to check.

Google is not the first to buckle. The curl project ended its bug bounty in January 2026 for the same reason. HackerOne stopped accepting new Internet Bug Bounty submissions in March. Intel recently froze a program that paid up to $100,000 per flaw, and Linux maintainers reported being swamped by bogus CVE filings.

Why it matters for builders

If your team runs AI agents that scan code, patch dependencies, or file security reports, this is a direct warning. Automated findings need a human verification gate before they leave your pipeline. Volume without validation is a liability that lands on someone else's desk, and the same pattern shows up anywhere agents generate work for humans to review, from support tickets to code review.

The second effect is smaller but real: open-source security disclosure just lost a paid channel. A genuine flaw in a project like Go now has fewer places to go, and unpaid reports to volunteer maintainers tend to sit longer. If you depend on open-source software, the pipeline that protects it is now thinner.

Sources: Google OSS VRP rules - TechCrunch - The Verge

Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

5 October 2026

Updated

5 October 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.