signalTechCrunch AI2026-10-05
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated submissions that are mostly invalid. The company promises an update in the first quarter of 2027. Open source maintainers were reportedly overwhelmed by reports containing hallucinations.
- for who
- Open source maintainers and security researchers who rely on Google's bug bounty program
- what changes
- They no longer receive rewards or validation for open source vulnerabilities through this program until it resumes, and they must seek other bounty avenues.
- to do
- Participants are encouraged to submit findings to Google's other bug bounty programs in the meantime.
key points
- Google paused open source bug bounty on October 1, 2026
- Rise in AI-generated invalid submissions caused the pause
- Update promised by Q1 2027; other programs remain open
#AI spam#bug bounty#open source security
score
score 6 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source