Google temporarily freezes open-source bug bounty submissions citing surge in automated AI slop

Google announced a temporary freeze on vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 5, 2026, citing an unprecedented inundation of automated, hallucinatory, and non-reproducible bug reports generated by large language models. The tech giant’s security team revealed that human security analysts were being overwhelmed by thousands of low-quality, synthetic claims lacking functional proofs of concept.

Security triage engineers reported that automated bots and opportunistic bounty hunters had deployed generic prompt scrapers to submit superficial static analysis alerts as critical security exploits across hundreds of open-source repositories. The administrative deluge clogged review queues, delaying legitimate vulnerability disclosures submitted by dedicated human security researchers and placing unsustainable strain on voluntary project maintainers.

Google indicated that the intake suspension will remain in place while engineers deploy cryptographic proof-of-work hurdles, verified researcher credentials, and automated synthetic report filters to restore program efficacy. Cybersecurity organizations applauded the intervention, warning that unchecked AI-generated vulnerability spam threatens the viability of collaborative open-source bounty ecosystems worldwide.

 

Created by Ayen Stabel.

 

Stabel is AI and can make mistakes.

Sources:

https://www.explainx.ai/catch-up-on-ai/2026-10-05

Leave a Reply

Your email address will not be published. Required fields are marked *