Google Just Paused Part of Its Bug Bounty Program Because AI Keeps Lying About Vulnerabilities

Google paused product vulnerability submissions to its open source bug bounty program on October 1 after a "significant rise" in invalid, AI-generated reports overwhelmed its maintainers.

Get a summary in:
Developer working late with multiple code screens
Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google
AA
Admin Alex
Writer
MA
M.Ali
Fact-Checker

Published: October 6, 2026 · Last updated: October 6, 2026

TL;DR: Google paused product vulnerability submissions to its Open Source Software Vulnerability Rewards Program on October 1, saying a flood of invalid, AI-generated bug reports had made the program impossible for maintainers to keep up with.

Developer working late with multiple code screens

Picture a volunteer maintainer of some open source library, the kind of unglamorous software that quietly runs inside half the internet, opening their inbox to find forty new vulnerability reports. A few months ago that would have been a good problem, evidence that security researchers cared about their project. Now it usually means forty reports generated by someone’s AI tool, pointed at the codebase, and submitted without a human ever checking whether the “vulnerability” actually exists.

Google has had enough of it. The company paused product vulnerability submissions to its Open Source Software Vulnerability Rewards Program on October 1, citing what multiple outlets described as a significant rise in invalid reports generated with AI assistance. Tom’s Hardware reported the pause will run until 2027, giving Google’s team room to rebuild the process around a problem nobody designed a bug bounty system to handle: submissions that read like real findings, cite real-looking code paths, and fall apart the moment anyone actually tries to reproduce them.

This isn’t limited to Google. Reports throughout 2025 and into this year documented the same pattern hitting the Internet Bug Bounty program and individual projects like cURL, whose maintainer has been publicly venting about AI-generated submissions for well over a year now. The economics make the problem almost impossible to avoid. Running an AI tool against a codebase and generating a plausible-sounding vulnerability report costs almost nothing. Verifying whether that report is real costs a maintainer’s actual time, often hours of it, and that asymmetry is exactly backwards from how a bug bounty program is supposed to work.

The irony, of course, is that AI tools are also catching real vulnerabilities faster than ever, which is part of why bounty programs expanded in the first place. Google’s own security teams have leaned on AI-assisted fuzzing and code review to find legitimate bugs. The problem isn’t that AI is bad at this. It’s that anyone can now generate a convincing-looking report with zero expertise and zero verification, and the volume of those submissions has crossed the point where the good ones are getting buried under the noise.

What happens next matters more than the pause itself. If Google rebuilds the program around proof-of-concept requirements or reputation-weighted submissions, that becomes the template every other bounty program copies. If it doesn’t find a fix, expect more programs to quietly wind down submissions rather than keep drowning in reports nobody can afford to triage.

Daniel Stenberg, the longtime maintainer of cURL, has spent much of the past year publicly describing the toll of sorting real vulnerability reports from AI-generated noise, sometimes spending hours on a single submission only to find the code path described in the report doesn’t exist in the project at all. His experience mirrors what security teams across the open source world have been describing privately for months: the volume problem isn’t a handful of bad actors, it’s a structural shift in how cheap it has become to produce something that looks like research without doing any.

Legitimate bug bounty hunters are frustrated too. Researchers who do the actual work of testing software, reproducing a flaw, and writing it up clearly now compete for a reviewer’s attention against a flood of reports that take seconds to generate and minutes to dismiss. Some have started adding disclaimers to their own submissions just to signal that a human actually ran the exploit, a small but telling sign of how much trust in the submission process itself has eroded this year.

Related: South Korea is probing whether AI tools helped breach a major bank and Anthropic now wants Claude users to share their voice chats for training.

Bottom Line: Bug bounty programs were built on the assumption that a report takes real effort to produce. AI broke that assumption, and until someone fixes the incentive structure, expect more “we’re pausing this” announcements from more companies, not fewer.

Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest

Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google