<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9" -->

---
title: Google froze its open source bug bounty program due to a...
description: Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated, AI-generated submissions,...
canonical: https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions | daily.dev
og:description: Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated, AI-generated submissions,...
og:url: https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9
og:image: https://api.daily.dev/og/posts/I37v04fX9.png
og:image:alt: Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

**[TechCrunch](https://daily.dev/sources/tc)** · 1 min read · 0 upvotes · 0 comments

## Summary

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated, AI-generated submissions, most of which are invalid or contain hallucinated vulnerabilities. The pause overwhelmed Google engineers and open source maintainers, and the company says it will provide an update in the first quarter of 2027. Participants are directed to Google's other bug bounty programs in the meantime.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions>

## Questions this post answers

### Why did Google pause its open source software vulnerability rewards program?

Google paused the program as of October 1 due to a significant rise in automated, AI-generated submissions, the vast majority of which were invalid or contained hallucinations. Engineers and open source maintainers were overwhelmed by reviewing these low-quality reports. Google said it would provide an update on the program's status in the first quarter of 2027.

_Developers tracking the fallout of AI-generated bug reports can follow updates like this on daily.dev._

### Can I still submit vulnerability reports to Google's bug bounty programs?

Product vulnerability submissions to the Open Source Software Vulnerability Rewards Program ended October 1, with no new submissions accepted until an update arrives in the first quarter of 2027. Researchers are encouraged to use Google's other bug bounty programs in the meantime rather than the paused open source track.

_Security researchers weighing where to submit findings can keep up with bounty program changes via daily.dev._

## Similar posts on daily.dev

- [Internet Bug Bounty program hits pause on payouts](https://daily.dev/posts/internet-bug-bounty-program-hits-pause-on-payouts-etorfdare) · InfoWorld · 1 upvotes · 0 comments
- [Bug bounty isn’t dead, but the old model is breaking](https://daily.dev/posts/bug-bounty-isn-t-dead-but-the-old-model-is-breaking-wbwl54kmh) · Aikido Security · 1 upvotes · 1 comments
- [GitHub will start paying some bug bounty hunters in swag instead of cash](https://daily.dev/posts/github-will-start-paying-some-bug-bounty-hunters-in-swag-instead-of-cash-aa2efuue8) · The New Stack · 0 upvotes · 1 comments
- [The Wonders of AI: We Are Retiring Our Bug Bounty Program](https://daily.dev/posts/the-wonders-of-ai-we-are-retiring-our-bug-bounty-program-dpolkxtt7) · Hacker News · 22 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#google](https://daily.dev/tags/google)

[View this post on daily.dev](https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions","url":"https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9"},"datePublished":"2026-10-04T20:33:29.414Z","dateModified":"2026-10-04T21:36:12.044Z","description":"Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a significant rise in automated, AI-generated submissions,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/29bb2f7b10b2a5ef9ac962d15ae4b00b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/29bb2f7b10b2a5ef9ac962d15ae4b00b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"TechCrunch","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"TechCrunch","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tc","url":"https://daily.dev/sources/tc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,google","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"TechCrunch","item":"https://daily.dev/sources/tc"},{"@type":"ListItem","position":3,"name":"Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions-i37v04fx9#faq","mainEntity":[{"@type":"Question","name":"Why did Google pause its open source software vulnerability rewards program?","acceptedAnswer":{"@type":"Answer","text":"Google paused the program as of October 1 due to a significant rise in automated, AI-generated submissions, the vast majority of which were invalid or contained hallucinations. Engineers and open source maintainers were overwhelmed by reviewing these low-quality reports. Google said it would provide an update on the program's status in the first quarter of 2027. Developers tracking the fallout of AI-generated bug reports can follow updates like this on daily.dev."}},{"@type":"Question","name":"Can I still submit vulnerability reports to Google's bug bounty programs?","acceptedAnswer":{"@type":"Answer","text":"Product vulnerability submissions to the Open Source Software Vulnerability Rewards Program ended October 1, with no new submissions accepted until an update arrives in the first quarter of 2027. Researchers are encouraged to use Google's other bug bounty programs in the meantime rather than the paused open source track. Security researchers weighing where to submit findings can keep up with bounty program changes via daily.dev."}}]}
```

