Security
Google Has Frozen Its Open-Source Bug Bounty Because of Machine-Generated Reports. curl Got There First, for the Same Reason
Google has stopped accepting product vulnerability reports for its own open-source projects, citing a surge in automated submissions that are mostly invalid. It kept supply chain reports open, and that split says what the real problem is.
MAI
Google has stopped accepting new vulnerability reports for its own open-source code. The reason it gave is not a budget cut or a reorganisation. It is that too many of the reports arriving are machine-generated and wrong.
The notice went up on Google's Bug Hunters site and its VRP account: "We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports." The explanation is one sentence long — the pause is "due to a significant rise in automated submissions, the vast majority of which are not valid." Submissions made after 1 October 2026 fall under the freeze. Google says it will say more about reforming the programme in the first quarter of 2027.
What is actually closed
The Open Source Software Vulnerability Rewards Program launched in August 2022 and covers Google's own open-source projects — Go, Angular, Protocol Buffers and the rest — paying between $100 and $31,337 for a valid finding. Only part of it has shut.
| Report type | Status |
|---|---|
| OSS VRP product vulnerability reports, filed after 1 Oct 2026 | Not accepted |
| OSS VRP supply chain reports | Still accepted |
| Reports already submitted | Unaffected, still being handled |
| Patch Rewards (paying for security improvements to OSS) | Open, up to $15,000 |
| Cloud VRP | Open |
That split is the most informative detail in the announcement. A product vulnerability report is a claim: here is a flaw in this code, here is roughly why it matters. A language model will produce one on demand, in correct English, with plausible file paths and a confident severity rating, and a triager cannot dismiss it without reading the code. A supply chain report tends to rest on an artifact someone can check — a credential in a repository, a misconfigured build, a dependency that resolves somewhere it should not. Google has kept open the category where claims carry their own evidence and closed the one where they do not.
curl got there first
This is not Google discovering something new. On 22 January 2026 the curl project announced it was ending its HackerOne bounty, taking its last submissions through 31 January and moving to its own process on 1 February. Daniel Stenberg was blunter than Google about why.
The main goal with shutting down the bounty is to remove the incentive for people to submit crap and non-well researched reports to us.
And, on the position a volunteer project finds itself in:
We are just a small single open source project with a small number of active maintainers. It is not in our power to change how all these people and their slop machines work. We need to make moves to ensure our survival and intact mental health.
Django and Node.js have added guardrails of their own. The pattern was already clear nine months ago. What changed this week is who it reached.
The asymmetry the bounty was built on
A bug bounty works because of an imbalance that used to run in the defender's favour. Finding a real vulnerability took skill and days; reading a report took an engineer an hour. Pay for the hard half, absorb the easy half, and the arithmetic holds. Generative models did not make the first half easier. They made producing something that looks like the first half nearly free, which means the programme now pays triage costs on volume it never priced for.
Google had already tried the cheaper fix. Earlier this year it published rule updates to the OSS VRP explicitly meant to "filter out low-quality reports and focus on real-world impact." Tightening the rules did not work; the freeze is the escalation. That sequence matters more than the freeze itself, because Google is the participant best equipped to absorb the problem. It paid out $17.1 million to more than 700 researchers in 2025, and over $81.6 million since 2010. It has full-time staff for this. If tightened rules plus a paid triage team is not enough, the volunteer maintainer reading reports after work has no move left except the one curl made.
What the repair will cost
Whatever Google announces in early 2027 will almost certainly gate submissions behind something harder to fake than prose — reproduction artifacts, a crash, a working test case, or reputation accrued elsewhere on the platform. That is the right direction and it has a price. The open front door was how an unknown researcher with no track record and one good finding got taken seriously. Raising the evidentiary bar raises it for them too, and the people flooding the queue are not the ones who will be deterred.
The thing to watch is not whether Google's programme comes back. It is whether what comes back is still open to a stranger.
Sources: Google halts open-source bug bounty program amid AI spam surge — BleepingComputer · AI slop submissions force Google to freeze its open-source bug bounty — Help Net Security · Streamlining Google's OSS VRP: Key Rule Updates — Google Bug Hunters · Curl ending bug bounty program after flood of AI slop reports — BleepingComputer · curl Shuts Down Bug Bounty Program After Flood of AI Slop Reports — Socket