Google Suspends Open-Source Bug Bounty Program Amid AI Spam Onslaught
Google has temporarily suspended one of the tech industry’s most esteemed cybersecurity initiatives. The Open Source Software Vulnerability Reward Program (OSS VRP) has been put on hold as of October 1, 2026. This decision comes in response to a significant increase in automated, AI-generated submissions that have inundated its engineering teams and open-source project maintainers.
The OSS VRP, which was inaugurated in 2022, offers rewards to security researchers who privately disclose vulnerabilities in Google’s open-source projects. These projects include but are not limited to Go, Angular, and Protocol Buffers. However, the advent of large language models has simplified the process of mass-generating plausible vulnerability reports.
According to Google, the overwhelming majority of the recent influx of submissions were invalid. These included AI hallucinations, fabricated code paths, and non-existent security flaws. Reviewers were dedicating hundreds of work hours to debunk synthetic claims rather than investigating genuine threats.
In an official post, Google announced the suspension is “due to a significant rise in automated submissions, the vast majority of which are not valid.” The company has pledged to revamp and restructure the program, with an update anticipated in Q1 2027. In the interim, researchers are being redirected to Google’s Cloud VRP and Patch Rewards Program.
This decision marks a turning point for the wider bug bounty industry, as AI tools increasingly blur the distinction between legitimate security research and automated noise.
Source: TechCrunch – October 4, 2026
