Google Halt Open Source Bug Bounties – AI “Slop” Flood

AI Report Flood Pauses Open-Source Bounties
AI Report Flood Pauses Open-Source Bounties

HOC Shorts

Google officially suspended product vulnerability reports under its Open Source Software Vulnerability Reward Program (OSS VRP).

  • The Cause: An overwhelming surge in low-quality, automated “AI slop” and synthetic bug reports flooded security teams, with the vast majority determined to be invalid.
  • Scope Exceptions: The pause applies strictly to OSS VRP product vulnerability submissions; supply chain reports and reports via the Google Cloud VRP remain active.
  • Next Steps: Google plans to restructure the submission and triage framework, with an operational update scheduled for Q1 2027.

Quick Summary

Google announced an operational freeze on product vulnerability submissions for its flagship Open Source Software Vulnerability Reward Program (OSS VRP). The decision comes as automated, LLM-generated bug reports—often containing hallucinated vulnerabilities or low-effort speculative findings—overwhelmed security triage teams and repository maintainers.

While AI models have significantly accelerated legitimate code auditing, their accessibility has triggered a wave of automated “bug-hunting” scripts submitted en masse by researchers seeking payouts, paralyzing crowdsourced vulnerability management.

Key Details & Program Scope

  • The Trigger: Google stated the temporary halt was driven by a “significant rise in agooutomated submissions, the vast majority of which are not valid”.
  • What Is Paused: Product vulnerability disclosures targeting Google-maintained open-source projects under the OSS VRP.
    What Remains Active:

    • Supply Chain Disclosures: Supply chain vulnerability reporting under OSS VRP continues unaffected.
    • Google Cloud Repositories: Security reports impacting Google Cloud products can still be submitted via the Google Cloud VRP.
    • Patch Rewards Program: Proactive contributions improving open-source security postures remain eligible for rewards.
  • Timeline: Google will use the pause to redesign its intake verification controls and submission criteria, with an official status update slated for Q1 2027.

Google posted on X,

We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.

Broader Industry Trend: The “AI Noise” Crisis

Google is not the first major entity to encounter operational friction due to synthetic bug reports. The incident reflects a growing structural challenge across open-source maintainers and bug bounty platforms:

[LLM / Automated Scanner] ──► Generates Speculative / Hallucinated Bug
│
▼
[Mass Submission to Bounty Portals]
│
▼
[Triage Queue Flooded with Low-Effort Noise]
│
▼
[Maintainer Burnout / Program Discontinuation]

  • Prior Program Closures: Early-stage examples include the curl project ending its HackerOne bounty initiative after automated AI submissions created severe triage fatigue for its maintainers.
  • Platform Interventions: Platforms like HackerOne and Bugcrowd have increasingly implemented strict spam-filtering protocols to penalize researchers submitting hallucinated technical claims, unverified static-analysis outputs, or non-reproducible code snippets.

OSS VRP Status Matrix

Program Channel Status Alternative / Next Steps
OSS VRP Product Vulnerabilities PAUSED Submissions halted until Q1 2027 update
OSS VRP Supply Chain Security ACTIVE Continue reporting via standard VRP portal
Google Cloud Product Repos ACTIVE Submit via Google Cloud VRP channel
Open Source Patch Rewards ACTIVE Submit defensive hardening patches for reward

You can check more info Google Open Source Software Vulnerability Reward Program Rules here.

Join Our Club

Enter your Email address to receive notifications | Join over Million Followers

Previous Article
Golden Ticket Attacks_ Detection & Fix

Understanding Golden Ticket Attacks: Detection & Fix

Related Posts