Your AI found a bug in Google's code. Google has stopped taking those reports.

Google froze product vulnerability submissions to its open-source bug bounty on 1 October 2026 after a flood of AI-written reports, nine months after curl killed its own program for the same reason.

By Yash Malviya

Published

Silhouette of a programmer coding in a dark room, focusing on the screen with lines of code
Photo: Alberlan Barros / Pexels

Google quietly closed the front door

Google logo
Google INC / Wikimedia Commons (public domain)

On 1 October 2026, Google's bug bounty team added one line to its own rules page: "As of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP." The Open Source Software Vulnerability Reward Program has paid researchers since 2022 for finding flaws in the open-source code Google publishes, from Bazel to Go to Angular. One of its two main report categories is now shut.

The reason came from Google's own @GoogleVRP account the same evening: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid." Not a budget cut, not a reorganization. Too many machine-written reports that were wrong.

What survives says more than the pause does. Supply chain compromises, meaning the ability to tamper with source code, a build pipeline or a signing key, still pay $3,133.70 to $31,337 on flagship projects. The reward table now carries a dash in every single column of the "Product vulnerabilities" row. Reports filed before 1 October are still being processed, some Google Cloud repositories can route product bugs through the Cloud VRP instead, and Google has committed to an update in Q1 2027.

This was the second cut, not the first

Google did not jump straight to a freeze, which is the part most coverage skipped. On 19 March 2026, three members of its security team, Camille Schneider, Jessica Zhang and Hayden Blauzvern, published a post explaining why the rules were already tightening. Their opening line: "Over the past few weeks, we've seen a massive surge in AI-generated reports."

That round introduced project tiers OT0 to OT3 and demanded harder proof: memory corruption reports against flagship and important projects now needed exact OSS-Fuzz reproduction steps against an existing fuzz target, or a patch already merged upstream. An April revision stripped rewards and even credit for product vulnerabilities in the two lower tiers. The post named both failure modes precisely: "AI-generated reports that contain incorrect information or 'hallucinations' about how a vulnerability might be triggered," and a flood of reports that point at a real coding error but "have negligible security impact given the project's security model or are not in reachable codepaths."

Six months of raising the bar did not hold the line. That, not the pause itself, is the news.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”

Google Bug Hunters (@GoogleVRP), 1 Oct 2026
Vivid close-up of code on a computer screen showcasing programming details
Sending a vulnerability report now costs a researcher minutes. Reading one still costs a maintainer hours. Photo: Godfrey Atima / Pexels

curl got there first and said the quiet part out loud

The precedent is nine months old. On 26 January 2026, curl lead maintainer Daniel Stenberg wrote: "There is no longer a curl bug-bounty program. It officially stops on January 31, 2026." It had run since April 2019 on HackerOne and it worked: 87 confirmed vulnerabilities and more than $100,000 paid out to researchers.

Then the signal collapsed. Stenberg's numbers are blunt. For years the share of submissions that turned out to be real vulnerabilities sat "somewhere north of 15%." From 2025 it fell below 5%. "Not even one in twenty was real," he wrote.

Stenberg named three trends, and only one of them is AI: the slop, human researchers doing worse than before, and reporters who "try too hard to twist whatever they find into something horribly bad and a critical vulnerability, but they rarely actively contribute to actually improve curl." HackerOne data he obtained showed curl's inbound volume rising sharply over four quarters while peer programs at Ruby, Node and Rails stayed flat or dipped. His explanation for being hit harder than average is uncomfortable for the whole model: the money was the draw.

curl's response was total. No monetary reward at any severity, no HackerOne, reports by GitHub private vulnerability reporting or email to the security team, and a promise to "continue to immediately ban and publicly ridicule everyone who submits AI slop to the project."

The economics explain which half Google kept

Point a language model at a public repository and it will produce a confident, well-formatted vulnerability report in minutes. Triage cost did not move: a human still reads it, still tries to reproduce it, still writes the rejection. When the cost of sending collapses and the cost of reading does not, a program that pays per accepted bug becomes a subsidy for guessing, and a plausible-sounding guess is what these models are best at producing. We covered why AI models hallucinate separately.

“The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk.”

Daniel Stenberg, curl lead maintainer, 26 Jan 2026

It also explains what Google kept. You cannot guess your way into a leaked package-manager credential or a compromised signing key. Supply chain findings are verifiable in a way "this parser might overflow" is not, so the payout stayed where fabrication is hardest.

It is not happening everywhere, and AI does find real bugs

The headline writes itself as "AI broke bug bounties," and that is too broad. In July 2025, Bugcrowd founder Casey Ellis told TechCrunch "AI is widely used in most submissions, but it hasn't yet caused a significant spike in low-quality 'slop' reports," while noting an overall rise of 500 submissions a week. Mozilla spokesperson Damiano DeMonte said Firefox had "not seen a substantial increase in invalid or low-quality bug reports that would appear to be AI-generated," with rejections steady at five or six a month, under 10% of the monthly total. HackerOne co-founder Michiel Prins did acknowledge "a rise in false positives" and shipped an AI-assisted triage product in response. The damage is concentrated, and the programs hit hardest are the small, high-profile, cash-paying ones.

The other half of the picture is that AI finds genuine vulnerabilities. Google's own Big Sleep agent, built with DeepMind and Project Zero, reported its first 20 flaws in open-source software including FFmpeg and ImageMagick in August 2025. The procedural difference is the entire difference. "To ensure high quality and actionable reports, we have a human expert in the loop before reporting, but each vulnerability was found and reproduced by the AI agent without human intervention," Google spokesperson Kimberly Samra said at the time. Google is now building models explicitly for this work, which is why Gemini 4 Argon ships to vetted defenders first.

Our take

The same company that markets AI vulnerability hunting has stopped accepting the output of AI vulnerability hunting from strangers. That is not hypocrisy, it is a verification problem with a price tag, and Google's two rounds of rule changes are a reasonable read of it: pay for the findings a human can confirm cheaply, stop paying for the ones that cost three engineers an afternoon to disprove. If you use a model to look for security bugs, the useful lesson is Samra's sentence, not Stenberg's. Reproduce it yourself, build the fuzz target, write the patch, and then file. A report you have not verified is not a contribution, and after 1 October it is not even worth money.

Frequently asked questions

What exactly did Google stop accepting?

Product vulnerability reports submitted to the Open Source Software Vulnerability Reward Program, as of 1 October 2026. That is the category covering flaws in Google's own open-source code, such as memory corruption in a parser.

Can you still get paid for finding bugs in Google's open-source code?

Yes, for supply chain compromises, meaning the ability to tamper with source code, a build pipeline or a signing key. Those still pay $3,133.70 to $31,337 on flagship projects. Some Google Cloud repositories can also route product bugs through the Cloud VRP instead.

Does this affect reports already submitted?

No. Google says the change does not affect product vulnerabilities submitted before 1 October 2026, and outstanding reports are unaffected.

Why did curl go further than Google?

curl dropped monetary rewards at every severity and left HackerOne entirely. Daniel Stenberg's reasoning was that the money itself was drawing in low-effort submissions, and HackerOne data showed curl's report volume rising sharply while peer programs at Ruby, Node and Rails stayed flat.

Does AI actually find real vulnerabilities?

Yes. Google's Big Sleep agent, built with DeepMind and Project Zero, reported its first 20 flaws in open-source software including FFmpeg and ImageMagick in August 2025. Google said a human expert reviewed each report before it was filed, even though the agent found and reproduced each bug on its own.

Sources

What each one is, and whose it is.

  1. Documentation
  2. OtherThe vendor’s own
  3. 3

    Streamlining Google's OSS VRP: Key Rule Updates, Google Bug Hunters (March 19, 2026)

    Vendor announcement
  4. 4

    The end of the curl bug-bounty, daniel.haxx.se (Daniel Stenberg) (January 26, 2026)

    OtherIndependent of the vendor
  5. Press reportIndependent of the vendor
  6. Press reportIndependent of the vendor
  7. Press reportIndependent of the vendor