Google just pulled the plug on its open source bug bounty program. Not trimmed it, not restructured it — paused the whole thing. As of October 1, the Open Source Software Vulnerability Rewards Program (OSS VRP) stopped accepting product vulnerability submissions, and the company says it will give an update on the program’s future by Q1 2027. That is an eternity in internet time.

The reason? A flood of AI-generated bug reports that, in Google’s own words, were “the vast majority… not valid.” Engineers and maintainers were spending more time manually validating code than actually fixing real vulnerabilities. Sound familiar? It should — because this has been building for months, and Google is just the biggest name to break first.
The End of a 14-Year Experiment
Google’s OSS VRP launched in 2012. For over a decade, it was a model for how big tech could collaborate with outside security researchers — find a flaw in Google’s open source code, write it up, get paid. The program covered projects like Angular, Go, BoringSSL, and TensorFlow. It was the kind of program that made open source security feel like a genuine partnership.
That partnership is now on life support. Google’s announcement on X and the OSS VRP rules page was blunt: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.” The company encouraged researchers to submit to other Google VRP programs or pursue the Patch Rewards Program instead. Supply chain reports — the ones covering compromised build pipelines and tampered packages — are unaffected. For some repositories tied to Google Cloud, product bugs can still be filed through the Cloud VRP.
But the route most people actually used — find a flaw in a public Google project, write it up, get paid — is gone. At least until Google figures out what comes next.
curl Saw This Coming
Daniel Stenberg, the creator of curl, saw the writing on the wall months ago. In January 2026, he shut down curl’s HackerOne bug bounty program entirely. The numbers were brutal: by 2025, fewer than 5 percent of submissions identified a real vulnerability. In the first 21 days of 2026 alone, the project received 20 reports. Not one was valid.
“The never-ending slop submissions take a serious mental toll to manage,” Stenberg wrote. His solution was radical: remove the monetary rewards entirely, move reporting to GitHub’s private vulnerability reporting, and publicly ban and ridicule anyone who submits AI slop. The goal, he said, was to “remove the incentive for people to submit crap and non-well researched reports to us.”
curl is one of the most widely used open source tools on the planet — it is in your browser, your phone, your car, your smart fridge. If curl’s maintainers could not keep up with the noise, what chance does a smaller project have?
The Economics of Hallucination
Here is what changed: the cost of generating something that looks like a professional vulnerability report is now nearly zero. A script can point an LLM at a repository and churn out a convincing-looking report in minutes — complete with a severity rating and a confident proof of concept that, more often than not, does not work.
Vlad Ionescu, co-founder and CTO of RunSybil, a startup that builds AI-powered bug hunters, put it plainly: “People are receiving reports that sound reasonable, they look technically correct… It turns out it was just a hallucination all along. The technical details were just made up by the LLM.”
That is the core problem. AI-generated submissions are not obviously broken. They are formatted well, they sound plausible, and they take longer to debunk than obviously poor ones. A human reviewer has to actually read the code, trace the logic, and prove the report wrong — which takes far more time than the LLM spent generating it in the first place. It is the same dynamic I described in my piece on spotting AI-generated phishing emails — the better the output looks, the more dangerous the noise becomes.
The Cloud Security Alliance documented the scale of this in a March 2026 research note. Bugcrowd recorded a 334 percent spike in submission queue length over three weeks attributable to unvalidated AI automation. CVE publication volume hit 48,185 in 2025 — a ninth consecutive record year — while the National Vulnerability Database’s enrichment analysis capacity covered only 28 percent of newly disclosed entries, down from 46.2 percent in 2024. FIRST’s 2026 forecast projects a median of 59,427 CVEs this year, with upper-bound scenarios exceeding 117,000.
We are not just drowning in AI-generated bug reports. We are drowning in vulnerabilities, period — and the AI noise is making it harder to find the real ones.
What This Means for the Rest of Us
Google’s pause is not an isolated event. It is a signal. GitHub tightened its submission requirements after acknowledging it could no longer separate real findings from noise. The Synack blog noted that “programs across the industry are grappling with the same challenge, and some have shut down entirely.” Django’s security team was hit with AI-fabricated reports. CycloneDX shut down its program. Apache Log4j’s volunteers reviewed 67 submissions in a matter of months — an exhausting volume for an unpaid team.
If you are running an open source project, this should keep you up at night. The traditional bug bounty model — post a scope, offer rewards, wait for researchers to find bugs — assumes that the bottleneck is the cost of finding vulnerabilities. AI has broken that assumption. The bottleneck is now the cost of triaging reports, and that cost has gone up, not down.
For developers and security teams, the lesson is clear: you need better filtering, not more submissions. I put together a practical framework for this in my AI deployment security checklist — the same principles apply to vulnerability management. Automate the first pass. Require reproducible proof of concept. And do not be afraid to cut off channels that are doing more harm than good. The same discipline I outlined for using AI text detectors without getting burned applies here: trust but verify, and never let automation replace human judgment on the final call.
The Bigger Picture
There is an irony here that is hard to miss. AI is making it easier to find vulnerabilities — Google’s own Gemini 3.5 Flash Cyber model demonstrated 100 percent reliable RCE exploit generation in under two hours. Anthropic’s red team showed Claude turning 18 Firefox patches into 8 working exploits, the first in under an hour. The same technology that is flooding bug bounties with noise is also the most powerful vulnerability discovery tool we have ever built.
The market is noticing. HiddenLayer just raised $100 million because AI security is becoming the most honest market signal in tech — companies are paying real money for tools that can tell signal from noise, a trend I covered in my analysis of HiddenLayer’s $100M bet. That is the world we are living in: the same AI that creates the problem is also the only viable solution.
But here is what keeps me up at night as someone who manages an ICT division: we are building critical infrastructure on top of open source projects whose maintainers are unpaid volunteers. When those volunteers get flooded with AI slop, they burn out. When they burn out, patches slow down. When patches slow down, we all become vulnerable.
Google’s OSS VRP pause is a warning shot. The bug bounty model as we knew it is broken. What replaces it — whether that is AI-assisted triage, mandatory human verification, or something nobody has thought of yet — will shape the future of open source security. And if you are a Filipino developer or ICT manager relying on open source tools, this is not someone else’s problem. It is yours.
Stay sharp. Verify everything. And maybe, just maybe, do not let an LLM write your bug reports.