parallelquant
October 3, 2026 · Tom's Hardware

Google freezes open-source bug bounty over flood of AI-generated reports

Google suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program. It cited an influx of invalid, AI-driven reports.

Why it matters: Cheap AI-generated vulnerability reports are overwhelming the triage capacity that bounty programs depend on. If large programs retreat, genuine researchers lose a channel and open-source security gets weaker, a cost of AI scale that falls on maintainers.

Related updates