The Vibe Check
Google has officially put its Open Source Software Vulnerability Rewards Program on ice, and it’s giving major 'this is why we can’t have nice things' energy. As of October 1, the program is paused, and it’s not coming back until at least the first quarter of 2027.
The Plot Thickens
So, what actually happened? Real talk: the program was meant to reward cybersecurity experts for finding legit security flaws in Google’s open source code. Instead, the company got buried in a mountain of automated, invalid submissions.
According to Google, they’ve seen a massive spike in reports generated by AI that are straight-up wrong—or as the tech world calls them, hallucinations. Google engineers and the people who maintain the open source code were lowkey overwhelmed trying to sift through all that digital trash to find the one or two needles in the haystack. It turns out that when you make it easy for AI to "find" bugs, it just ends up generating a ton of noise that wastes everyone’s time.
Why it matters
This is a classic case of AI marketing vs. AI reality. While we’re all out here hyped about what AI can do, this situation proves it can also be a total nightmare for developers. If a tech giant like Google can’t even handle the flood of AI-generated junk, it makes you wonder how other platforms are going to keep their systems from drowning in fake reports. If you were looking to score some bug bounties, you’ll have to hit up Google’s other programs for now—and maybe let the dust settle on this one.




