The punchline is hard to miss

Google has spent the last two years putting AI coding assistants, bug finders and report writers into the hands of security researchers. This week it acknowledged that its own review pipeline could not keep up with the output. The company that sells the machinery of automated submission paused part of its bounty program because machine-generated junk outran the humans paid to read it.

What happened is not mysterious. Google's statement blamed "a significant rise in automated submissions, the vast majority of which are not valid." Reporting described engineers and open-source maintainers buried in claims that were invalid or hallucinated: exploit paths that led nowhere, vulnerabilities that did not exist. Every report still had to be opened, read and checked by a person. Reviewers burned time doing homework for bugs that were never real.

Cybersecurity researchers warned last year that AI-generated slop could become a serious threat to bug bounty programs. Flooding an intake queue with plausible-looking bugs turned out to be one of the easiest parts to automate.

Check the scope before the obituary

The freeze is narrower than the headlines suggest. Supply-chain reports, the part of the program covering compromised build pipelines and tampered packages, keep running. Anything filed before October 1 will still be processed. For some repositories tied to Google Cloud products, researchers can route product bugs through the Cloud VRP instead.

What is gone, for now, is the route most researchers used: find a flaw in one of Google's public projects, write it up and get paid.

The economics underneath

A bug bounty pays for findings. AI tooling has collapsed the cost of producing something that looks like a finding to near zero. The cost of verifying one stayed human. Each hallucinated report can consume the same reviewer time as a real one, while the submitter pays nothing for that review. When generating noise is nearly free and filtering it stays expensive, the rational move is to stop accepting submissions. Google just made it.

This asymmetry is not confined to bug bounties. Any system that rewards human-verified submissions, including grant programs, journals and freelance platforms, now has to price in automated junk. Google's pause is a clear case of the review pipeline breaking before the submission pipeline.

Where legitimate hunters go

Google is pointing researchers toward its other vulnerability reward programs and the Patch Rewards Program, which pays for accepted patches rather than reports. Expect the same response elsewhere: frozen intakes, stronger proof required up front, and payment moving from write-ups to merged fixes.

The cost of that shift is real. Legitimate hunters, the people doing the work the program was built to attract, now wait until the first quarter of 2027 to learn what replaces it. The slop did not just waste reviewer time. It took the venue away from people who were using it properly.

Sources

  1. [1] TechCrunch — “Google froze its open source bug bounty program”Read source
  2. [2] Neowin — “Google issues complete OSS VRP bug bounty pause”Read source