Google has stopped paying for one of the most common kinds of open-source bug report, and it is blaming automated submissions. As of October 1, the company's Open Source Software Vulnerability Reward Program (OSS VRP) no longer accepts product vulnerability reports, which are the reports about flaws in the code of Google's own open-source projects. Google says it will share an update in the first quarter of 2027.
The explanation came straight from the program's account on X. In a post on October 1, Google VRP wrote that "this pause is due to a significant rise in automated submissions, the vast majority of which are not valid," and pointed researchers to the updated OSS VRP rules page on Google Bug Hunters. Tom's Hardware and TechCrunch both describe the flood as largely AI-generated reports that claimed bugs which turned out to be invalid or hallucinated, leaving engineers and maintainers to spend their time disproving them.

What is paused and what still pays
The pause is narrower than a headline like "Google froze its bug bounty" suggests. Based on Google's post and the rules page, here is where things stand:
- Paused: new product vulnerability reports against Google's open-source repositories.
- Still open: OSS VRP supply chain reports, such as compromised dependencies or build pipelines.
- Still handled: any product vulnerability report submitted before October 1.
- Possible alternative: some issues in Google Cloud repositories that affect Cloud products can still go through the Google Cloud VRP, according to Tom's Hardware.
- Also suggested by Google: its other VRP programs, and the Patch Rewards Program, which pays for fixes rather than reports.
That last suggestion says a lot. Pointing people toward patches means pointing them toward work that is much harder to fake, since a patch has to compile and pass review. A report only has to sound convincing.
Google isn't the first to hit this wall
What makes this more than a one-company story is the pattern over the past nine months. We pulled the dates together from each program's own notices and the coverage around them:
| When | Program | What happened |
|---|---|---|
| Jan 31, 2026 | curl | Ended its HackerOne bug bounty and stopped paying for security reports |
| Mar 27, 2026 | HackerOne Internet Bug Bounty | Paused new submissions while still paying queued ones |
| September 2026 | Intel | Paid bounty listed as suspended, replaced by a no-reward disclosure program (no reason given) |
| Oct 1, 2026 | Google OSS VRP | Paused product vulnerability reports until at least Q1 2027 |
Intel is the odd one out because it never said why. Tom's Hardware, which covered the change on September 19, speculated that AI-driven reports may have played a role, so treat that one as unconfirmed.
The curl case is the best documented, and its numbers show why maintainers are giving up on cash rewards. In his post announcing the end of the bounty, curl lead Daniel Stenberg wrote that the program produced 87 confirmed vulnerabilities and paid more than $100,000 since 2019. In earlier years "somewhere north of 15%" of submissions turned out to be real, but starting in 2025 that dropped below 5%. Run the math and it looks like this: at 15%, a maintainer reads about seven reports to find one real bug, and at 5% it's twenty. The real bugs didn't disappear, but the reading time per real bug roughly tripled, and for a small volunteer team that is the whole budget.
The same math works out to an average of roughly $1,150 in bounty money per confirmed curl vulnerability ($100,000 divided by 87), which is a bargain for a tool as widely used as curl. The money was never the expensive part. The hours spent disproving fake reports were, and that's the cost Google is now pointing at too.
Our take
If you hunt bugs for income, this is a clear signal to shift toward work that proves itself. Supply chain findings, patch submissions, and reports with a working proof of concept are still welcome, and they're exactly the kind of thing an automated tool has trouble faking. If you maintain an open-source project with a bounty, curl's experience suggests that removing the money removes most of the junk, and Stenberg later wrote on LinkedIn that the AI slop reports had stopped arriving.
For everyone else, the worry is simple. Fewer paid programs means fewer incentives for skilled people to look closely at widely used code, at the same time that attackers have the same AI tools. We'll be watching what Google's Q1 2027 update looks like, especially whether it adds stricter proof requirements rather than keeping the doors closed.
Source: Google VRP on X and OSS VRP rules; Tom's Hardware; TechCrunch; curl / Daniel Stenberg.
