20 signals
HOlO V1 IS LIVEone ranked AI digest a day, scored in publicREAD HOW IT WORKS →HOlO V2 STARTSyour X account, your signals, every day
back to all articles
signalTechCrunch AI2026-10-05

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated submissions that are mostly invalid. The company promises an update in the first quarter of 2027. Open source maintainers were reportedly overwhelmed by reports containing hallucinations.

for who
Open source maintainers and security researchers who rely on Google's bug bounty program
what changes
They no longer receive rewards or validation for open source vulnerabilities through this program until it resumes, and they must seek other bounty avenues.
to do
Participants are encouraged to submit findings to Google's other bug bounty programs in the meantime.
key points
  • Google paused open source bug bounty on October 1, 2026
  • Rise in AI-generated invalid submissions caused the pause
  • Update promised by Q1 2027; other programs remain open
#AI spam#bug bounty#open source security
score
score 6 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source
Post on X