AI-Generated ‘Slop’ Forces Google to Suspend Open Source Bug Bounty Program
Google has officially suspended its Open Source Software Vulnerability Rewards Program following an overwhelming surge in automated, AI-generated bug reports. The pause, which took effect on October 1, comes as security engineers and open-source maintainers find themselves inundated with low-quality, invalid, and often hallucinated vulnerability claims. The tech giant plans to keep the program on hold while it evaluates how to address the influx, with an update expected in the first quarter of 2027.
Bug bounty programs have long relied on ethical hackers and cybersecurity researchers to identify and report security flaws in exchange for monetary rewards. However, the democratization of generative AI tools has enabled bad actors and low-effort participants to mass-produce automated reports. Instead of highlighting genuine security threats, these AI-generated submissions frequently hallucinate non-existent vulnerabilities, forcing Google’s internal teams to waste valuable time and resources filtering through the noise.
While the open-source arm of its reward initiative is temporarily offline, Google has clarified that its other vulnerability reward programs remain active. Researchers are being redirected to these alternative channels while the company works on a long-term solution to combat automated spam. This suspension highlights a growing industry-wide challenge where AI tools, designed to assist in threat detection, are instead being leveraged to disrupt the very systems meant to secure digital infrastructure.
Key Takeaways
- Google has paused its Open Source Software Vulnerability Rewards Program due to an overwhelming volume of invalid, AI-generated bug submissions.
- The suspension took effect on October 1, with Google planning to provide an official update on the program's status in the first quarter of 2027.
- While the open-source bounty program is frozen, Google's other cybersecurity reward initiatives remain operational for researchers.
Editor’s Analysis & Impact
The suspension of Google’s open-source bug bounty program is a watershed moment highlighting the double-edged sword of generative AI in cybersecurity. While AI can assist defenders in identifying code vulnerabilities, its accessibility has lowered the barrier to entry for low-quality, automated submissions. This ‘AI slop’ threatens the sustainability of crowdsourced security. Maintainers, who are already stretched thin, cannot afford to spend hours debunking hallucinated security flaws. Moving forward, organizations will likely need to implement AI-driven filtering triage systems to validate submissions before they reach human reviewers. This incident will likely prompt other tech giants to re-evaluate their own public bounty programs, potentially leading to stricter verification processes and a shift toward invite-only or highly vetted researcher pools.
Frequently Asked Questions
Q: Why did Google pause its open-source bug bounty program?
A: Google suspended the program due to a massive influx of automated, AI-generated submissions. The vast majority of these reports were invalid or contained 'hallucinated' vulnerabilities, which overwhelmed the company's engineers and open-source maintainers.
Q: When will the program resume?
A: The program was paused on October 1, and Google has stated it will provide an update on the status of the initiative in the first quarter of 2027.
Q: Can researchers still submit bugs to Google?
A: Yes. While the open-source vulnerability rewards program is temporarily frozen, Google's other bug bounty programs remain active and open to submissions.