§ News
By AI Blog Editor
Oct 5, 2026 · 10 min read
Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program
Google paused product vulnerability submissions to its OSS VRP on October 1, citing a "significant rise in automated submissions, the vast majority of which are not valid." The first frontier lab to publicly concede defeat to AI slop.

On October 4, 2026, Google posted a short note to X. As of October 1, it had stopped accepting product vulnerability reports to its Open Source Software Vulnerability Rewards Program — the OSS VRP, launched in 2022 as the company's channel for paying external researchers who found bugs in Google-maintained open-source projects. The reason, in Google's own words: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."
The sentence is short. The thing it describes is not. AI-generated vulnerability reports have gotten noisy enough that one of the three big American AI labs has publicly conceded that a defensive-security channel it has run for four years can no longer be staffed the obvious way.
What's actually paused, and what isn't
The pause is narrower than the headlines suggest, and the shape of what Google kept open is informative:
- Product reports to OSS VRP — paused.
- Supply-chain reports — still accepted.
- Cloud VRP (Google Cloud repositories) — still accepted.
- Patch Rewards Program — still accepted; Google explicitly points researchers there as an alternative.
- Reports submitted before October 1 — processed as normal.
Google committed to shipping an update on OSS VRP's submission process in Q1 2027. That is three to five months of a defensive channel being closed, measured in a timeline where the frontier labs ship a new model about once a quarter. By the time the program reopens, the generation of models filling the inbox will be two or three versions newer.
The part Google kept open — supply chain and cloud — are the categories where a report tends to come from a researcher with a specific, reproducible finding rather than from a reporter who pointed a chatbot at a GitHub repository and clicked submit. The gated-by-friction channels survived. The open-anyone-can-submit channel did not.
This has been building for eighteen months
The curl project got there first. Daniel Stenberg, who maintains curl and libcurl, has been writing about AI slop in his HackerOne inbox at increasing length since early 2025. In February 2026 he closed the curl HackerOne program outright; a month later he reopened it with a tighter policy and the explicit standing instruction that any reporter whose submission the maintainers judge to be AI slop is banned on sight. By mid-2026 Stenberg had the volume numbered: roughly one AI-generated vulnerability report every eighteen hours, against a pre-AI baseline of one per week.
The Internet Bug Bounty, which triages for projects that cannot staff their own program, has been publicly dealing with the same thing. Intel and the Linux kernel maintainers have each reported the pattern. What makes Google's announcement different is who is making it. The curl project is one person plus a small group of volunteers. The Linux kernel is a federation of maintainers answering to a dozen employers. Google is Google. If the OSS VRP cannot absorb automated submissions, the number of defensive programs that can is small and getting smaller.

The structural irony is impossible to miss
The AI company and the targeted-by-AI company are the same company. Google launched Gemini 4 Argon under the Fairwind Program five days before pausing the OSS VRP. It also sells Gemini 3 Pro, 3 Flash, and Flash-Lite to anyone with a Google account — models that will produce a plausible-looking vulnerability report in thirty seconds if asked. The channel that pays external researchers to find bugs in Google's open-source projects is being flooded by output from the kind of models that Google itself sells.
Google is not uniquely responsible. OpenAI, Anthropic, Alibaba, and Moonshot all ship code-aware LLMs that can write a convincing-at-first-glance bug report with no actual bug behind it. But Google is in the position of running one of the three biggest frontier labs and a bug bounty program that has now been paused by the output of frontier labs collectively. That the specific lab pausing its program is also the one that just launched the most recent frontier model would, in a less busy news cycle, read as satire.
What Google is probably redesigning
The Q1 2027 update will not be a "we trained a classifier to spot AI slop" announcement. Classifiers have been attempted. The models have improved. By 2026, as Stenberg's own reporting puts it, the submissions have gotten technically accurate without becoming valid — hallucinated causality dressed as a reproducer. Classifiers lose that arms race in six months.
More plausible redesigns: proof-of-work for reporters (bonded deposits, compute cost, time investment), accredited-researcher gating (only HackerOne-vetted or similar can submit), or a narrower submission surface so a smaller triage team can own what remains. Each of those is being floated across the industry. Whichever version Google ships will set the template for the Patch Rewards Program, the Cloud VRP, and probably Chrome's VRP within six months — not because the other programs are failing yet, but because the AI-slop volume keeps rising and the triage math has one answer.
Any of those designs excludes a class of researchers who historically found real bugs. That is the cost of a defensive-security channel being gated: the signal gets dropped with the noise. OSS VRP paid out around $190K across 2022–2024 (Google's own public figures) to researchers who were overwhelmingly not accredited, not well-connected, and often based in countries where accredited-only gating is a filter they cannot clear. Those are the researchers who will not file after the reopening.
What to watch
- Does the Q1 2027 reopening change the submission contract? If OSS VRP comes back with the same open-to-anyone terms, Google is betting classifiers can beat the models. If it comes back gated — accredited researchers, deposits, proof-of-work — Google has conceded that the open-submission model is dead. Either answer sets the next decade of coordinated-disclosure practice.
- Does another frontier lab publicly follow? OpenAI's own VRP and Anthropic's responsible-disclosure channel both face the same inbound. If either announces a pause before Q1 2027, the problem is officially industry-wide and reaches regulators by H1 2027. If neither does, the question is whether they are triaging better or just reporting less honestly.
- Does OSS VRP-eligible reporting migrate to project-specific channels, and get lost there? Many of the projects covered (Angular, Go, Fuchsia, Bazel) accept vuln reports directly. If a measurable share of OSS VRP reporting moves to those channels and the maintainers triage no better than Google did, the OSS VRP's absence shows up as an uptick in zero-day disclosure times for Google-maintained OSS. Hard to see in Q4 2026; visible by mid-2027.
- Does Intel or the Internet Bug Bounty formalise a pause? IBB is the most-likely next shoe to drop — it operates at smaller scale with fewer triagers per report. A formal pause there would mean the AI-slop problem has crossed from large-lab discretionary programs to the connective tissue of OSS security.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 moreLetters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.