Google froze its open source bug bounty program across the United States this week after facing an unprecedented wave of automated vulnerability claims.

The technology giant confirmed that the temporary halt applies strictly to new product flaw reports within its open-source security initiatives. Officials stated that the suspension is necessary to prevent automated tools from overwhelming the review pipeline.
This disruption impacts the broader science and tech sector as cybersecurity teams scramble to filter out low-quality data.
The sudden policy shift highlights a growing operational crisis for major technology platforms managing community-driven defense networks. As artificial intelligence tools become more accessible, bad actors and automated systems generate vast quantities of hallucinated vulnerability reports.
Reviewers and maintainers now spend countless hours sorting through invalid claims instead of addressing real digital threats.
Why Google froze its open source bug bounty program
Industry analysts have tracked a sharp decline in signal-to-noise ratios across multiple security platforms over the past year. Automated bots now flood digital intake forms with plausible-looking text that ultimately lacks any technical substance.
- Automated submissions have risen exponentially.
- The vast majority of incoming files lack validity.
- Maintainers are drowning in AI-generated hallucinations.
This administrative burden severely compromises the core mission of vulnerability reward programs. Security engineers must manually verify every single notification to ensure actual network risks are not missed.
When fake alerts multiply, genuine security research gets buried under mountains of digital noise. Cybersecurity specialists warn that this phenomenon threatens the integrity of collaborative software development worldwide.
Industry groups note that legitimate researchers now struggle to gain visibility for critical zero-day discoveries. The sheer volume of synthetic traffic obscures authentic warnings that protect global infrastructure.
Google has announced that the pause on new product flaw submissions will remain active until 2027. This multi-year timeline gives engineering teams adequate space to rebuild their intake filters and upgrade automated detection systems.
During this extended hiatus, the organization plans to develop robust filtering mechanisms to block low-quality synthetic data permanently. Maintainers intend to restore a streamlined reporting environment before welcoming new community contributions back into the ecosystem.
Background and next steps
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions TechCrunchGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations Tom’s Hardware‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissions IT ProGoogle’s OSS VRP Pause on New Product Reports NeoTeoAI makes the discovery of legitimate cybersecurity threats more difficult htxt.co.za
The story remains in motion, and readers should watch for official updates as more facts are confirmed.
Public interest is likely to stay high while new details emerge from reporters and officials.
Early claims should be treated cautiously until primary sources corroborate them.
Coverage of Google froze its open continues to evolve as more details become available.
Readers watching Google froze its open should look for official updates in the coming hours.
