Google has paused its Open Source Software Vulnerability Rewards Program after a sharp increase in automated submissions that the company says were overwhelmingly invalid. TechCrunch reported on October 4 that the pause began October 1 and is expected to remain in place while Google reassesses the program, with an update promised in the first quarter of 2027.

The program was designed to reward security researchers who identify vulnerabilities in Google’s open-source software. According to the TechCrunch report, Google engineers and open-source maintainers became inundated with submissions that either did not describe real vulnerabilities or relied on hallucinated technical explanations. Google attributed the decision to what it called a significant rise in automated reports and said the vast majority did not hold up under review.

Anonymous reviewers separate credible vulnerability evidence from distorted automated reports.
A convincing report still needs evidence that reviewers can reproduce and assess.

That distinction matters because a vulnerability report is not useful merely because it sounds technically plausible. It must describe an actual flaw, explain how the issue can be reached or triggered, and give reviewers enough evidence to assess the risk. The report indicates that automated submissions shifted more of that verification burden onto the humans responsible for triage, creating a queue in which invalid claims competed with potentially legitimate findings for attention.

The pause is a practical warning about the economics of AI-assisted security research. Automated tools can produce candidate findings and polished reports at high speed, but the TechCrunch account suggests that review capacity did not scale with submission volume. That means the limiting resource was no longer the generation of possible bugs; it was the expert time required to determine which reports were real, relevant and actionable. This is an inference from the cited surge and the reported strain on engineers and maintainers, rather than a separate claim from Google.

A rapid automated conveyor feeds reports into a narrow human inspection checkpoint.
The pause highlights how automated report generation can outpace expert security triage.

Google has not said in the report that it is abandoning vulnerability rewards altogether. Participants are being directed toward the company’s other bug-bounty programs during the pause, and the commitment to provide an update in the first quarter of 2027 leaves the future structure of the open-source program unresolved. The report does not specify what new filters, evidence standards or participation rules Google may adopt.

For security teams and open-source maintainers, the episode illustrates a broader governance problem surrounding automated research: lowering the cost of producing a report can raise the cost of validating every report that arrives. Google’s decision does not establish that AI-assisted vulnerability research is inherently unreliable. It does show, based on the company’s own explanation, that unverified automation can overwhelm a disclosure channel when report volume grows faster than human review capacity.