Google froze its bug bounty queue because the reports stopped costing anything
Google paused OSS VRP product vulnerability submissions on October 1 after a flood of invalid AI reports. What the pause says about the economics of verification.
Google pays a top reward of $31,337 for a valid security bug in its open source projects. As of October 1, most of that pipeline is closed, because the reports stopped being evidence of work. A model can produce one in seconds, and the queue proved it.
The pause covers product vulnerability submissions to the Open Source Software Vulnerability Reward Program, the bounty Google opened in August 2022 for projects like Bazel, Angular, Golang, and Fuchsia. Google's own explanation, posted to X and the program rules page: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." An update is promised in the first quarter of 2027. Supply chain reports still count, and product bugs in Google Cloud repositories can route through the Cloud VRP for now.
The operational detail matters more than the announcement. Tom's Hardware reported that engineers and open source maintainers were being buried under thousands of AI-generated reports claiming bugs that turned out to be invalid or unexploitable hallucinations. Time that used to go toward fixing real vulnerabilities went to manual validation instead. When the cost of reading submissions exceeds the value of the few real ones inside, closing the queue is the rational move. Google took it.
None of this was hidden. In July 2025, TechCrunch reported security researchers warning that AI slop and fake reports were exhausting bug bounty programs across the industry. Since then, Linux kernel maintainers said they were "completely overwhelmed" as AI-powered bug hunters pushed the kernel toward a record 2,000 CVEs per release, and Intel suspended a bounty that paid as much as $100,000 per flaw. The program that closed this week launched in August 2022. The pressure that ended it was visible the whole time, and the response stayed the same: keep paying for real bugs, absorb the flood, hope triage holds. It stopped holding.
The reason this one is worth attention is what a bounty measures. A bounty pays for a scarce thing: a real, exploitable flaw plus the labor to document it well enough to verify. Text models collapsed the cost of the document. A report that reads like a vulnerability now costs nothing to write, so the reading, reproducing, and rejecting all land on the payer. The signal did not get noisier. The cost of faking the signal dropped to zero, and the program's economics broke on the payer's side.
Anyone shipping agent features to anonymous users is consuming the same free tier Google just cut off. Generation is cheap everywhere. Verification is still priced like it was in 2022, and verification is the part you cannot fake your way out of, because a security report has a binary ending: the bug reproduces or it does not. Google's eventual fix will probably look like pricing, not filtering. Maybe identity gates, maybe proof-of-work attached to each report, maybe payments that only clear after reproduction. All of it amounts to moving some cost of proof back onto the submitter.
The reward for a real bug is still $31,337. What changed is that the claim is now worthless until someone reproduces it, and the reproducing is the whole job.
Sources: TechCrunch on the pause, the OSS VRP rules page, the GoogleVRP announcement on X, Tom's Hardware on the maintainer overload, the 2022 program announcement, TechCrunch's 2025 warning on AI slop, Tom's Hardware on Linux kernel CVE overload, and Tom's Hardware on Intel's suspended bounty.
Comments ()