Google Freezes Open Source Bug Bounties as AI 'Slop' Breaks the System

AI-generated image · US National Wire
The pause on the Open Source Software Vulnerability Rewards Program signals a crisis in the creator economy for security researchers: when AI automates the noise, the meritocracy collapses.
For years, the bug bounty economy operated on a simple, meritocratic premise: find a genuine vulnerability, report it, and get paid. But as I've tracked across the platform landscape, the introduction of generative AI often turns these incentive structures into a game of volume over value. Google is now the first major player to hit the brakes when that volume becomes unsustainable.
As TechCrunch first reported, Google has paused its Open Source Software Vulnerability Rewards Program effective October 1. The company cited a "significant rise" in automated submissions as the primary driver for the freeze. In statements posted to the program's website and X, Google noted that the vast majority of these automated reports were invalid.
This isn't just a technical glitch; it's a monetization crisis. As TechCrunch notes, cybersecurity experts had previously warned that "AI slop" posed a serious risk to the viability of these reward systems. When the barrier to entry for submitting a report drops to near zero thanks to AI, the signal-to-noise ratio evaporates.
The human cost of this automation is borne by the reviewers. TechCrunch, citing Tom’s Hardware, reports that Google engineers and open source maintainers were overwhelmed by a flood of reports that were either completely invalid or riddled with AI hallucinations. When the workforce responsible for verifying the 'merit' of a submission is buried under synthetic noise, the entire payout system breaks.
Google has promised to provide an update on the program in the first quarter of 2027. In the interim, the company is directing participants toward its other existing bug bounty programs.
**Malik's Take:** This is a canary in the coal mine for any platform that pays for user-generated contributions. When AI allows bad actors or low-effort participants to flood a system with plausible-sounding but fake entries, the cost of verification eventually outweighs the value of the reward. Google isn't just pausing a program; they are admitting that the current model of rewarding vulnerability discovery cannot survive an automated onslaught without a total redesign of how 'value' is verified.

