Google halts open source bug bounty program amid surge in AI

Google has halted its open source bug bounty program until next year, citing a “significant rise” in AI submissions that has overwhelmed their systems. This change, effective October 1, 2026, alters how the company manages its Open Source Software Vulnerability Rewards Program, which previously rewarded researchers for discovering vulnerabilities in its open source software.

The surge in submissions has created challenges for Google engineers and open source maintainers, who have found that many of these entries are either invalid or contain hallucinations–essentially, false reports that don’t represent real vulnerabilities. As Google noted, “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”

Participants in the program can expect an update from Google in the first quarter of 2027, as the company reevaluates its strategy for handling these submissions. Meanwhile, researchers seeking opportunities are encouraged to explore Google’s other bug bounty programs, which may still be active and offer alternative ways to report vulnerabilities.

Share your love
The Genius Geek
The Genius Geek

Newsletter Updates

Enter your email address below and subscribe to our newsletter