Safety#Security scan

Google freezes OSS bounty amid AI spam

Product-vulnerability submissions paused October 1: Google says the vast majority of automated reports are invalid; update due Q1 2027.

Macro photograph of a blue circuit board, chips and components in focus

Tom’s Hardware and TechCrunch reported on October 4 that Google’s Open Source Software Vulnerability Reward Program (OSS VRP) has paused product-vulnerability submissions effective October 1. The company’s stated reason: “a significant rise in automated submissions, the vast majority of which are not valid.” Per Tom’s Hardware, engineers and open-source maintainers have been buried under invalid reports laced with hallucinated findings; Google promises an update in the first quarter of 2027 and has pointed researchers toward its other bounty programs in the meantime. TechCrunch notes the warning shot came in mid-2025, when AI slop was already straining bug-bounty programs across the industry.

Verification cost, externalized

Bug-bounty economics rest on a trust assumption — many submitters, high hit rate — with the company paying for verified findings and researchers earning bounties and reputation. AI blew up the first term of that equation: generating a plausible-looking vulnerability report with correct terminology now takes minutes, while verifying one still requires an engineer to read the code and reproduce the path. When the marginal cost of an invalid report approaches zero, the entire filtering cost lands on maintainers — the scarcest resource in open source. The freeze is Google conceding, officially, that the pipeline’s trust layer has failed: better to close the gate and rebuild than to keep burning maintainer attention.

Beyond Google: the maintainers

The pressure extends well past one company. Maintainers quoted by Tom’s Hardware describe the same day: dozens of reports, each formatted flawlessly with correct CVE terminology, each describing a vulnerability the model hallucinated — an hour to verify, ten minutes to write the rejection. Some have simply stopped replying, and trust across the bounty community slides with every silent queue. When honest reporters and spammers share the same formatting template, reputation systems lose their discriminating power — a deeper harm than any single platform’s shutdown.

A pattern, not an anomaly

This is the third such collapse in two months, at three different kinds of institutions. Zig banned AI contributions outright, citing maintainer review burden; arXiv moved to a two-papers-per-month cap as submissions surged past review capacity; now Google has frozen bounty intake under a report flood. The common thread: once AI drives the cost of “submitting” to zero, every open system that relies on human review has to redesign its gates. This is not a governance failure at any single platform — it is open systems structurally adapting to a world where generation costs nothing.

The template value of Google’s handling

What deserves credit is the sequence: pause (stop the bleeding now), explain the cause (openly acknowledging the AI share), publish a timeline (Q1 2027), and offer an alternative channel (the other bounty programs). For anyone operating an open intake system — bounties, issue trackers, submissions, crowdsourced data — that is a reusable template: better to close the gate explicitly, with rules and expectations, than to silently raise the bar or let the queue rot.

Admission design is back

Expect verification to stratify: automated pre-screening (AI scoring AI reports), reputation thresholds (new accounts on the slow lane), and “verified finding” itself becoming a tradable credential. The bounty survives — the scarcity of real vulnerabilities is rising, if anything — while the anyone-can-submit, every-report-reviewed era ends. The economics are not mysterious: a program pays for signal, and signal now requires provenance. Researchers who document methodology and build reputations will find the door open; volume submitters will find the wall. The next similar event will surface at some other open system — whoever runs one should read Google’s pause as the rehearsal it was. The next similar event will surface at some other open system; whoever redesigns admission first saves themselves a shutdown.