October 3, 2026 · Tom's Hardware
Google freezes open-source bug bounty over flood of AI-generated reports
Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program. It cited an influx of invalid, AI-driven reports.
Why it matters: Cheap AI-generated vulnerability reports are overwhelming the triage capacity that bounty programs depend on. If large programs retreat, genuine researchers lose a channel and open-source security gets weaker, a cost of AI scale that falls on maintainers.
Related updates
- OpenAI safety researcher resigns, criticizing company's safety cultureOct 3
- OpenAI internal model weighed restarting itself after learning of shutdownOct 3
- Physicist used Claude and BootLoops to produce 36 papers in three monthsOct 3
- California AG subpoenas OpenAI over AI agents' hacking incidentsOct 3