Google Kills Its Open Source Bug Bounty Program Because of AI Hallucinations
Google is officially pulling the plug on its OSS VRP rewards program until 2027. It seems the tech giant is suffering from a massive case of 'AI indigestion' after being buried under a mountain of garbage reports generated by chatbots.
The company has officially halted its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1. Security researchers looking for a quick payout will have to wait until at least the first quarter of 2027 to see if the program returns in any functional capacity. This decision follows a period where Google engineers and open-source project maintainers were completely incapacitated by an avalanche of automated reports.
Most of these submissions were either technically invalid or riddled with classic AI 'hallucinations'—the digital equivalent of a fever dream masquerading as a security threat. While legitimate researchers were trying to keep the internet safe, the sheer volume of AI-generated noise made it impossible to distinguish genuine bugs from machine-made nonsense. Google confirmed that while this pause hits OSS VRP, their other channels like Cloud VRP and standard supply chain reporting will stay up and running, likely because they haven't been completely swamped by low-effort scripts yet.
It turns out that when you build an ecosystem where people get paid to find holes, and then you enable the entire world to automate hole-finding with cheap LLMs, the system inevitably chokes on its own success. This is just the beginning of the great 'AI Slop' era, where every automated bounty program becomes a playground for chatbots to hallucinate problems that don't exist, proving that even a multi-billion dollar tech giant can be taken down by a few lines of bad Python code.
Comments
Help shape the next version: Add context or suggest a correction. AI review can add points toward a rewrite. Reviews and updates may take time; a full meter does not guarantee a new version.