Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a flood of AI-generated invalid submissions that created an operational burden for engineers and open source maintainers.
Many reports contained what Google described as "hallucinations"—erroneous AI-generated content. The company expects to provide an update in the first quarter of 2027.
The OSS VRP offered cash rewards to researchers for identifying vulnerabilities in Google's open source software. The suspension reflects a structural problem: as AI tools become commodity security scanners, they flood crowdsourced programs with noise, forcing maintainers to spend cycles filtering instead of triaging genuine issues.
Cybersecurity experts warned last year that "AI slop" would degrade bug bounty economics. Google's move confirms the risk is not hypothetical. The incident demonstrates a new hidden cost of external security contributions—the validation and filtering overhead now required to separate signal from AI-generated junk.
Google is directing displaced researchers to its other existing bug bounty programs. The company did not disclose the scale of invalid submissions or the operational cost incurred.
For capital-efficient security operations, this creates a tension: crowdsourcing remains a cost-effective way to find zero-days, but AI-driven spam raises the per-submission triage cost enough to erode program margins. How other companies respond—whether they raise barriers to entry, add stricter validation gates, or simply accept higher filtering costs—will shape the economics of external vulnerability research.
