Google Freezes Open-Source Bug Bounty as AI Reports Flood Reviewers

Google has paused its Open Source Software Vulnerability Rewards Program. The pause started October 1, and Google said it will provide an update in the first quarter of 2027. TechCrunch
The program paid outside researchers who found security flaws in Google's open-source software. Google told researchers with work in progress to consider its other bug bounty programs.
Google blamed a sharp rise in automated submissions, with the vast majority invalid. Google described it as a volume problem in the review queue.
The freeze covers only one part of the program. Reports about flaws in products are paused. Disclosures about the supply chain, which deal with dependency information, remain open. Times of India Google linked the freeze to a rise in invalid AI-generated submissions. Tom's Hardware
In practice, the two queues work differently. A product report needs a reviewer to reproduce the bug, judge severity, and coordinate with maintainers on a fix. A supply-chain disclosure centers on dependency data and how a problem spreads downstream.
Google has adjusted these payouts before. It published criteria in 2023 for reporting bugs in AI products, to help researchers test AI safety and security. Google Security Blog In the first year, that AI program brought in more than 150 reports and paid more than $55,000. Google Security Blog More recently, it started a patch rewards program for OSV-SCALIBR, its open-source tool for finding flaws in software dependencies. Google Security Blog
Taken together, that record shows a program that opens new areas while closing queues that stop working. New targets get rules and rewards. Tooling gets patch incentives. A noisy queue gets frozen.
The broader context here is familiar from past bounty programs. AI tools have made it cheap to produce a report that looks plausible. Checking it is still slow work. A reviewer must rebuild the software, trace the vulnerable code, test whether it can be exploited, and set a severity level. When volume rises and quality falls, reviewers spend time without making software safer.
In my view, the pause is less a step back from open-source security than a sign the payment model breaks under automation. Paying for each valid find works when candidates are hard to find. It fails when candidates are cheap to create and costly to reject. Adding more reviewers or higher payouts is unlikely to fix that on its own.
Looking at what this means for researchers, the short-term message is plain. High-volume, low-effort submissions do not just go unpaid. They can shut down the program itself. Researchers who show clear reproduction steps, evidence the bug can be exploited, and careful scoping will still be needed. Operators now need to make that work count, with stricter proof, reputation tracking, or automated pre-checks.
Worth flagging is the line Google drew. It kept the structured, machine-checkable supply-chain reports and paused the product reports that need more human judgment. That protects reviewer time now. Over time, it also suggests a path forward, with clearer formats, reproducible evidence, and automated checks before a person reviews. That kind of plumbing is unglamorous, but it is how open source gets more secure.


