The Bounty That Ate Itself: Google Suspends OSS VRP Product Reports as AI Slop Buries Maintainers
On October 1, 2026, Google stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Reward Program, blaming an avalanche of invalid AI-generated reports — the first mainstream bounty to publicly crack under machine-made bug spam, with a restart promised by Q1 2027.
On October 1, 2026, Google switched off one of the security world’s most trusted intake pipes. In an announcement posted on X that day, the company confirmed it would no longer accept product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) — and it committed to giving an update on the program’s future “in Q1 2027.” The official rules page on Google Bug Hunters now carries the same notice, dated October 1, 2026.
The reason, in Google’s own words, was “an influx of invalid AI-driven reports.” The submitters are not malicious. Most are people who downloaded the source of an open-source project, pointed an LLM or an automated bug-hunting agent at it, and forwarded whatever the model claimed to find. The problem is what the models claim to find usually isn’t there: the reports describe hallucinated code paths, invented function calls, and “vulnerabilities” that turn out to be ordinary behavior or simple coding errors with no security impact at all.
Security engineers and open-source maintainers on Google’s side were reportedly buried under thousands of these poorly written submissions, spending their days manually validating code that was never broken instead of fixing real, critical vulnerabilities. So Google did the math that every intake operation eventually does when the signal-to-noise ratio collapses: it shut the door.
What exactly was suspended
The freeze is narrower than the headlines suggest, and the boundaries matter for anyone who files reports:
- Suspended: product vulnerability submissions to OSS VRP, effective October 1, 2026 — the day of the announcement. Reports that claim code defects, logic flaws, or design bugs in Google’s public open-source repositories are no longer accepted.
- Still processed: anything filed before October 1. The freeze is not retroactive.
- Unaffected: supply chain submissions. The part of OSS VRP that covers compromised build pipelines and tampered packages continues as normal.
- Partial workaround: Cloud VRP. Google says product bugs can still be submitted through the Cloud Vulnerability Reward Program “for some Google Cloud repos impacting Google Cloud products.”
Google’s message to researchers in the meantime is blunt: “explore other VRP programs.”
OSS VRP was launched in August 2022 to reward discoveries of vulnerabilities in Google’s open-source portfolio — the ecosystem around projects the company maintains or funds. For four years it paid independent researchers for the painstaking, manual work of reading code, understanding it, and responsibly disclosing what they found. That skill requirement was the program’s implicit filter. Large language models removed it.
The pattern did not start with Google
What makes the Google decision significant is not that it’s surprising — it’s that it’s the largest program yet to confirm a pattern that smaller ones have been fighting for over a year.
The canary was curl. Daniel Stenberg, the project’s founder, documented the “death by a thousand slops” through 2025 as AI-generated security reports flooded the project’s HackerOne queue. One report claimed an HTTP/3 vulnerability and included function calls and behaviors that appear nowhere in the actual codebase. By mid-2025, curl reported that only about 5% of its bug bounty submissions were genuine vulnerabilities, with roughly 20% visibly AI-generated — and Stenberg noted the never-ending slop submissions took “a serious mental toll to manage and sometimes also a long time to debunk.” On January 31, 2026, the curl bug bounty program officially ended, almost seven years after it began.
The Linux kernel is the mid-scale version of the same story. AI-assisted bug hunters scouring the kernel’s roughly 40 million lines of code have pushed it toward a record 2,000 CVEs fixed per release — up from roughly 500 through much of the 6.x era — and maintainers have described themselves as “completely overwhelmed” by the volume. The finds include real flaws, but they arrive buried in mountains of low-priority and outright bogus work. Earlier this year, Linux ended support for older network drivers partly due to an influx of false AI-generated bug reports. Linus Torvalds had already called the kernel’s security list “unmanageable” back in May.
And just this month, Intel suspended a bug bounty program that paid up to $100,000 per flaw. The company never officially confirmed AI-generated reports as the cause, but security observers suspect exactly that.
The economics are unforgiving. A hallucinated report costs the submitter almost nothing to produce — a few cents of API calls and a copy-paste. Triaging it costs a skilled human anywhere from minutes to hours. Any intake channel that pays or credits for reports, without a way to price in that asymmetry, will eventually drown. Google is simply the biggest name yet to hit the wall.
What the freeze does — and doesn’t — fix
For genuine researchers, the immediate impact is a rerouting problem. Product bugs in Google’s open-source code must now go through Cloud VRP (where eligible) or vendor-direct disclosure channels. Google’s own rules note that AI-generated submissions were already barred from programs it funds — in March it told submitters to stop using AI to file reports — so the suspension is an admission that prohibition alone didn’t scale.
For the security ecosystem, the bigger question is what OSS VRP looks like when it comes back. The shape of the Q1 2027 restart is the real signal. Plausible mechanisms include mandatory proof-of-concept execution before a report enters triage, researcher reputation thresholds, or attestations that a human verified the claimed code path. Any of these would set a template that HackerOne-hosted programs — many facing identical slop pressure — could copy within a quarter.
There is also an uncomfortable irony worth naming: AI is simultaneously the best and worst thing to happen to vulnerability discovery. Google’s own threat intelligence team reported vulnerability disclosures doubling from 5,045 in January 2026 to 10,477 by July. Some of that increase is genuine capability — models and agents really do find real bugs, as Anthropic’s Mythos demonstrated days before this announcement by surfacing an authentication bypass in Rejetto HFS that was exploited in the wild within 24 hours of disclosure. The industry’s task is not to stop machine-assisted discovery; it’s to build intake systems that can distinguish the Mythos finds from the hallucinations at machine speed.
Why it matters
Google’s OSS VRP freeze is the moment the AI-slop problem in security stopped being an open-source maintenance anecdote and became Big Tech infrastructure policy. When the program that Google built to protect its own open-source ecosystem can no longer afford to read its mail, every smaller project watching from the sidelines loses its most optimistic argument — that the flood is survivable with enough volunteers.
The next checkpoint is Q1 2027, when Google has promised an update. Whether it reopens with gating, pivots to supply-chain-only coverage, or quietly sunsets product bounties will tell the rest of the industry how to price the cost of listening.
Sources
- [1] https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1
- [2] https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules
- [3] https://aiweekly.co/alerts/google-freezes-oss-vrp-product-bug-reports-after-ai-slop-flood
- [4] https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
- [5] https://www.tomshardware.com/software/linux/linux-kernel-nears-2-000-cves-per-release-as-ai-bug-hunters-scour-40-million-lines-of-code-maintainers-say-they-are-completely-overwhelmed