Google is pausing open source bug bounties because AI bug reports are overwhelming its reviewers

Vulnerability: Generative AI models are exceptionally good at code, and vibe coding is now spreading everywhere. So much so that many open source projects struggle with an unsustainable amount of contributions if they want to maintain a proper review process.

Google is temporarily suspending financial rewards for skilled bug hunters because its human staff cannot keep up with the current flood of automated reports. The “vast majority” of these submissions are slop, warns Google, and contain invalid information and hallucinated vulnerability data.

Tech Trivia: Which tech company launched the world’s first bug bounty program?

The program being suspended is Google’s Open Source Software Vulnerability Rewards Program (OSS VRP), which the company developed to encourage capable researchers to report vulnerabilities in Google’s own open source projects. Researchers get paid for their results and Google benefits from better, safer code in Go, Angular, Fuchsia and other major FOSS codebases.

Then came vibe coding. The Google Bug Hunters team recently announced that the OSS VRP is no longer accepting submissions about product vulnerabilities. The pause is due to a significant increase in automated reports that place too much burden on auditors. Furthermore, most of these Vibe-encoded reports are simply useless.

Google has also updated the OSS VRP rules so that the program will no longer accept new vulnerability reports submitted after October 1, while reports submitted before then are still being processed. Some Google Cloud repositories may still accept new reports, but the main VRP is being “reformatted” to deal with the new chaos that coding has brought to the open source world. Google plans to release an update on the future of the program in the first quarter of 2027.

Google makes a special exception for supply chain reports, which can have a huge reach compared to other “simpler” errors. Reports of particularly dangerous defects are also safe. In any case, Mountain View will refer skilled bug hunters looking for a reward to other VRPs that continue to accept reports, as well as to its Patch Rewards program.

Vibe coding is now penetrating every open source codebase with public access. Microsoft Edge, Linux and other large FOSS projects face the same problems as Google, while smaller teams have simply decided to close the door on AI-generated contributions to avoid being overwhelmed by the crowd.

Avatar photo
Written by

Mira Edora

Mira Edora is a writer and contributor at CKSOR, creating clear and engaging articles on current topics, technology, science, lifestyle, and stories of interest to readers. She enjoys researching new developments and presenting useful information in a simple, accessible way. Through her writing, Mira aims to keep readers informed with timely, informative, and easy-to-understand content.

Leave a Comment