- Google suspended product vulnerability submissions to its open-source bounty on October 1, citing a flood of invalid AI-driven reports, according to Tom's Hardware.
- Bounties pay for findings, but the cost of verifying them falls on the receiver. Tom's Hardware says staff were diverted from fixing real flaws.
- If you run or fund a bounty, measure the share of reports that are valid, and require a working proof that the flaw can be triggered.
When finding bugs gets cheap, checking them becomes the cost
A bug bounty is a simple trade. A company pays outside researchers to find flaws and report them privately. Until recently, finding a flaw was hard and costly. In our view, that kept reports scarce enough for a small team to review.
AI has changed one side of that trade. The lesson here is that the scarce resource is no longer the finding. It is the attention of the person who has to decide whether the finding is real.
What Google did
Google has stopped accepting one kind of report in its Open Source Software Vulnerability Reward Program (OSS VRP). As of October 1, product vulnerability submissions are suspended. Tom's Hardware reported the move on October 4 and says Google announced it in a post on X.
According to Tom's Hardware, the cause is an influx of invalid AI-driven reports. Google pointed participants to its other reward programs. It says it is reworking this part of the program and will report back by the end of the first quarter of 2027.
The suspension has limits. Product vulnerabilities submitted before October 1 are not affected. OSS VRP supply chain reports are not affected. Tom's Hardware also reports that Google may still accept some product reports through its Cloud VRP, for certain Google Cloud repositories that affect Cloud products.
How the flood happens
The suspended category covers code defects, logic flaws and design bugs in Google's public repositories. Tom's Hardware describes that work as slow, manual and skilled. It says large language models and automated bug-hunting scripts have nearly removed the cost and effort.
Tom's Hardware reports that Google engineers and maintainers were reportedly overwhelmed by thousands of weak submissions. It says the claimed bugs were invalid or could not be exploited. It calls them hallucinations: descriptions of flaws that do not exist.
Why a model invents a bug
A language model predicts text that looks right. Shown a block of code, it can write a fluent, confident account of a flaw, because that is what such reports usually look like. A language model on its own does not run the code, and a report written from it alone has nothing checking that the flaw is real.
A genuine report usually carries a proof of concept. That is a small working demonstration that triggers the flaw on purpose. If the demonstration fails, the report fails. A write-up without one needs a human to read it, run it and judge it.
The sender pays almost nothing. The receiver pays in hours. Email spam ran on the same arithmetic. When sending is free and reading costs time, volume stops being a sign of value.
Tom's Hardware says staff ended up validating code instead of fixing real, critical vulnerabilities. It does not say fixes were delayed. That step is our inference: if the same happens in projects you depend on, fixes could reach you later.
Other cases, with different evidence
Tom's Hardware places Google's move beside two others. Each rests on different evidence, so they should not be read as one measured trend.
The first is Linux. The outlet says kernel maintainers were "completely overwhelmed" by vulnerability findings earlier this month. It credits AI-powered bug hunters and cites a record 2,000 vulnerabilities per release. That is a count of reported findings. The report does not say they were false.
Separately, it notes that Linux ended support for older network drivers over false AI-generated bug reports. These are two different Linux items and should not be merged.
The second is Intel, which has paused its bounty scheme, where rewards reached $100,000 for a single flaw. Intel did not confirm AI reports as the reason. Tom's Hardware says experts suspect it, which is an inference rather than a finding.
What this means for your organisation
Most companies do not run a bounty at Google's scale. Many still depend on open-source code whose maintainers sit behind queues like these. Ask whether those maintainers have the capacity to separate real reports from noise.
Questions to put to your security team:
First, if we run a bounty or accept outside reports, what share of last quarter's submissions were valid? If nobody tracks it, start there.
Second, do our intake rules require a working proof of the flaw, not just a description? A requirement like that moves the checking cost back to the sender.
Third, which open-source projects do we rely on most, and do we support their maintainers with money, staff time or good-quality reports?
Fourth, are we using AI to find flaws in our own code? If so, who verifies the output, and how many hours does that take?
The line to remember
A bounty program prices the finding. AI has made findings cheap, so the price that matters now is the cost of checking. Google's pause is one program's answer, and its update is due in the first quarter of 2027.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Tom's Hardware.





