
Google Paused Its Open-Source Bug Bounty. AI Report Spam Is Why.
Mahmud Hasan
October 6, 2026
On October 1, Google quietly stopped accepting vulnerability reports to its open-source bug bounty program. The reason it gave reporters was blunt: a "significant rise in automated submissions, the vast majority of which are not valid." Translation: AI made it nearly free to file a bug report, and the flood of machine-generated slop has buried the humans who have to verify them.
Google is not alone. In the last few months, Intel suspended its bounty program, the creator of curl shut down its HackerOne page, and Linux kernel maintainers publicly said they were "completely overwhelmed" — all for the same reason. The bug bounty model, which has protected open-source software for decades, is breaking under the weight of reports nobody asked a human to write.
What Google actually paused
Google's Open Source Software Vulnerability Reward Program (OSS VRP) still exists, but its rules page now states plainly that "as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP." Google promised an update in Q1 2027, but gave no guarantee the door reopens.
The pause covers only product-vulnerability reports — the category where a researcher flags a defect in Google's public repositories. Supply-chain reports (which pay $500 to $31,337.70 depending on the project's importance) keep running, and Cloud repositories can still go through the separate Cloud VRP. Reports filed before the cutoff are unaffected. The Patch Rewards Program, which pays up to $15,000 for verified fixes rather than reports, also stays open.
Notice the pattern in what survived: every channel that still pays requires either a higher-stakes finding (supply chain) or an actual patch (verified code). The channel that died is the one that paid for claims.
It's not just Google — it's the whole triage economy
The same week Google froze its program, the Linux kernel's maintainers were describing their own version of the disaster. Greg Kroah-Hartman shared a slide ahead of this month's Kernel Recipes 2026 conference showing CVEs fixed per kernel release climbing from roughly 500 in the 6.x era to past 1,000 in 7.0, past 1,500 in 7.2 — and possibly past 2,000 when 7.3 lands. The codebase didn't quadruple; it stayed around 40 million lines. What changed is who's reading it.
Networking maintainer Jakub Kicinski said that between one-third and one-half of the 648 patches submitted to the net-next tree during the 7.3 cycle looked like AI-driven low-priority fixes and cleanups. His summary: "We are completely overwhelmed." Linus Torvalds had flagged it months earlier, writing in his 7.1-rc4 release post this May that the kernel's private security mailing list had become "almost entirely unmanageable" — report volume went from 2–3 per week two years ago to 5–10 per day in 2026.
And the flood is reshaping the kernel itself. Developers are now deleting old code partly to make it stop being a target: Andrew Lunn proposed removing nearly 28,000 lines of legacy networking drivers in April, the entire ISDN subsystem was cleared out earlier this year, and the FreeVxFS filesystem driver was dropped after its maintainer concluded it had become little more than target practice for automated checkers.
Intel, for its part, suspended a bounty program that had paid up to $100,000 per flaw and replaced it with a no-reward disclosure process through Intigriti. Intel didn't confirm AI slop caused the move, but researchers told Tom's Hardware that's exactly what happened. The creator of curl shut down the project's HackerOne bounty for the same reason.
The uncomfortable truth: the AI tools work. The economics don't.
It would be easy to read this as "AI can't find real bugs," but that's not what happened. The tools are genuinely good. A Chinese model, Z.ai's GLM-5.3, helped uncover more than 1,000 critical vulnerabilities across major open-source projects this year. In July, STAR Labs researcher Lee Jia Jie disclosed CVE-2026-53264, a use-after-free race in the kernel's net/sched code that gave local privilege escalation to root — found during an AI-assisted hunt on his first Linux kernel project. The bug had sat there for two or three years. He also reported two exploitable flaws in the perf events subsystem, one of them CVE-2026-64300. An AI system called KyleBot independently found the same net/sched bug days before the TyphoonPwn 2026 contest.
Jia Jie's own conclusion is the one everyone should quote: AI accelerated the hunt but still showed blind spots and reasoning failures — detailed subsystem knowledge remains what separates a real find from noise.
That's the actual asymmetry. Writing a plausible-sounding vulnerability report with an AI agent takes minutes and costs almost nothing. Verifying whether it describes a real, exploitable flaw takes a trained engineer reading actual code. When the reports were human-made, the effort of writing one roughly matched the effort of checking it. Now the ratio is a hundred to one, and every hallucinated report still demands a judgment call from someone who could otherwise be fixing a real bug.
What changes next
Google's Q1 2027 update will be the signal everyone watches. The likely paths are friction, not generosity: requiring a reproducible exploit before a report qualifies, demanding OSS-Fuzz confirmation, or keeping the door closed for product reports indefinitely while channeling hunters toward supply-chain reports and patch rewards. Watch HackerOne and Bugcrowd too — if the two biggest platforms adopt AI-submission screening, that's the new industry standard.
The kernel community already picked its answer. After debate at the 2025 Maintainers Summit, the rule settled at: AI can assist, but it cannot assume ownership. LLM-generated patches are barred from the staging subsystem except for legitimate security fixes, and guidance warns that unverified AI reports waste maintainer time. Kroah-Hartman, speaking on the SOSS podcast, drew the fuzzer analogy: when fuzzing first flooded the kernel with reports, Google supplied the triage resources — engineers who sorted the real crashes from noise, fixed the severe ones, and let interns learn on the rest. AI bug hunting has no such sponsor. His verdict on smaller projects facing the same flood: "I am actually worried about it."
The takeaway
If you run AI scanners against open-source code: Google's biggest payout channel for that output is gone until at least Q1 2027, and bulk-filing AI-generated reports is now the fastest way to get your program contributions flagged as noise. Do the verification yourself — reproduce it, write the exploit, confirm it with a fuzzer — before you file. The scarce resource in this market is no longer the finding. It's the hour of a human who will vouch for it.
References
- Google pauses open source bug bounty payouts after a flood of invalid AI reports — Pondero, October 5, 2026
- Google Pauses Open Source Bug Bounty Over AI Spam — Android Headlines, October 2026
- AI is finding thousands of bugs in Linux, and maintainers can barely keep up — TechSpot
- AI bug hunters swamp Linux maintainers — Fudzilla
- AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched — Infosecurity Magazine
Comments
More in Technology

A 9.9 in GitLab's AI Gateway — and Upgrading GitLab Won't Fix It
GitLab's self-hosted AI Gateway has a 9.9 sandbox-escape flaw — and patching GitLab itself won't fix it. Here's what's broken, who needs to act, and the pattern nobody's talking about.
Read more
Node.js Is Slowing Down on Purpose. The Reason Is a Maintainer Crisis.
One release a year, every release LTS — it sounds like a gift to developers. The numbers behind Node.js's schedule change tell a different story.
Read more
RAM Is Up 500% in a Year. Micron Just Extended the Shortage to 2028.
Memory prices are up fivefold in a year, and Micron's CEO says he cannot see when supply and demand rebalance. What the earnings call actually means for your next PC purchase.
Read more