Google pauses open source bug bounty program after rise in AI submissions
Brief
Companies like Google and Microsoft are finding much bigger numbers of vulnerabilities in their own products as a result of AI . But the same technology is leading to public reporting programs becoming overwhelmed by the mass submission of speculative, duplicated, or hallucinated findings.
Now, Google’s announced it has temporarily stopped accepting submissions to its open source bug bounty program, OSS VRP.
“Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
We’ve seen this happen before. In early 2026, curl ended its HackerOne bounty program after low-quality, often AI-generated submissions overwhelmed its small security team.
Intel also launched a new bug bounty program on Intigriti but there are no longer bounties available, reportedly in order to stop a flood of AI generated reports.
