TechCrunch reports that Google has paused its open source bug bounty program until next year. The company is blaming a "significant rise" in AI submissions.

The program in question is Google's Open Source Software Vulnerability Rewards Program. It paid researchers who found security holes in the company's open source software. In posts on X and on the program website, Google said the pause took effect on October 1. It promised "an update" in the first quarter of 2027.

Google's own explanation is short and blunt: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." Citing Tom's Hardware, TechCrunch says Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. In the meantime, Google is pointing participants to its other bug bounty programs.

People who watch security saw this coming. Last year, TechCrunch reported that cybersecurity experts were warning that AI slop posed a serious risk to bug bounty programs. Now one of the biggest names in tech has hit the brakes on one of its own.

If you have never dealt with a bug bounty, here is the simple version. A company says: find a real security flaw in our code, tell us privately, and we will pay you. It is a good deal on both sides. The company gets free eyes on its code, and researchers get paid for skill and patience. The catch is that every single report has to be read by a person who understands the code well enough to say yes, this is real, or no, it is not.

That is where AI changes the math. Writing a report that sounds convincing is now cheap. Checking it is still slow, careful human work. A report with a hallucination in it can send a maintainer chasing a bug that does not exist. Do that enough times and the people who keep the software safe spend their week reading fiction instead of fixing real problems. Google's word for the result was overwhelmed, and I believe it.

I have reviewed enough code to know that a confident description is not the same as a working fix. The same goes for security reports. A finding you can reproduce is gold. A finding you cannot reproduce is noise, and noise costs the people on the other end real hours.

I do not read this as the end of bug bounties, and I do not read it as AI being useless for security work. Researchers who use these tools well can find real flaws faster. The problem is volume without verification. Google said it will share an update early next year, and I would expect the program to come back with tighter rules about what counts as a valid submission.

That would be good for honest researchers, too. A cleaner queue means real findings get read sooner and paid sooner.

My advice if you use AI to hunt for bugs is simple. Reproduce the issue yourself before you hit submit. Include the steps that prove it. A report you have not tested is a guess, and a flood of guesses is exactly what got this program paused.