Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Google Froze Its Open Source Bug Bounty Program Over a 'Significant Rise' in AI Submissions

Google has frozen its open source bug bounty program after a "significant rise" in AI-generated submissions, TechCrunch reports. The move highlights how automated reports are straining bug bounty triage and raising new questions for open source security collaboration.

Published
Google因AI提交激增冻结开源漏洞赏金计划
Image source: techcrunch.com

Google has frozen its open source bug bounty program, TechCrunch reports, pointing to a "significant rise" in AI-generated submissions as the immediate cause. The move appears tied to automated security reports flooding human review queues.

Bug bounty programs are a long-standing part of the software security ecosystem: vendors publicly offer rewards to researchers who report vulnerabilities before attackers can exploit them, paying out according to severity. When AI tools mass-produce submissions, the cost of triaging genuine findings from noise climbs quickly, and valuable reports risk being buried.

TechCrunch frames the trend as "AI slop" overwhelming bug bounty programs. The outlet's headline ties the problem directly to a surge in AI submissions, suggesting the pressure comes not from ordinary growth in security research but from the sheer scale of automated content.

Google's decision to freeze rather than shut the program down suggests the company likely needs time to redesign how submissions are reviewed and filtered rather than abandoning the model outright. For security teams, the signal is worth watching: generative AI has lowered the barrier to filing vulnerability reports, which can surface genuine issues but also produces large volumes of duplicate, low-quality, or plausible-sounding hallucinated findings that dilute useful intelligence.

From a broader industry view, open source security already depends on limited contributions from volunteer researchers and vendors. When AI inflates submission volume beyond what humans can review, both the economics and the credibility of bounty programs come under scrutiny — a challenge many vendors may soon share.

What comes next is whether Google restores the program after reworking it, how it plans to filter AI-generated submissions, and whether other vendors follow with similar pauses or new review rules. The "AI-ification" of bug bounties is becoming a shared test for the security industry.

Why it matters

AI-generated submissions are raising the triage cost of bug bounties; if more vendors follow, the balance between human researchers and automated filings will reshape how open source security collaboration works.

GoogleSecurityOpen Source
Back to realtime news

Nearby Updates

All