Security/ google · bug-bounty · ai · open-source

Google pauses open-source bug bounty amid AI slop surge

Google has frozen its open-source bug bounty program after a flood of AI-generated vulnerability reports made the queue unmanageable, the company said.

Google has hit pause on its open-source bug bounty program, and the culprit is AI.

Google confirmed it has frozen new submissions to the program, pointing to a 'significant rise' in reports generated by AI tools. The company didn't break down how many of those reports were legitimate versus noise, but the freeze itself suggests the volume became unmanageable for the humans who have to triage each one. Google hasn't said how long the pause will last or what it plans to change before reopening submissions.

Bug bounty programs depend on a basic trade: researchers spend real effort finding real flaws, and companies pay for the privilege of fixing them before attackers do. AI tools are warping that trade by making it nearly free to generate a plausible-sounding vulnerability report, whether or not a real bug exists - which means triage teams now have to spend real effort just proving a negative.

Google is one of the best-resourced security teams in the industry, and it still couldn't keep up - smaller open-source projects running bounty programs on a volunteer's spare evenings don't stand a chance.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →