🔒Google Pauses Open Source Bug Bounty Program Due to AI Submissions
AI submissions overwhelm Google's bug bounty program
TL;DR
Google has paused its open source bug bounty program due to a surge in AI-generated submissions, overwhelming engineers and maintainers. The program will resume in 2027 with updates.
Google has paused its Open Source Software Vulnerability Rewards Program due to an overwhelming number of AI-generated submissions, most of which were invalid or contained hallucinations. This pause highlights the challenges AI poses to traditional bug bounty programs, affecting the workflow of security researchers and open source maintainers. The program was paused as of October 1, 2023, and will resume in the first quarter of 2027 with updates to address the issue of invalid submissions. Participants are encouraged to consider Google's other bug bounty programs.

Key Points
Google's Open Source Software Vulnerability Rewards Program paused as of October 1, 2023.
The majority of AI submissions were invalid or contained hallucinations.
Google engineers and open source maintainers were overwhelmed by the influx of reports.
Participants are encouraged to consider Google's other bug bounty programs.
The program will resume in the first quarter of 2027 with updates.
Why It Matters
Security researchers and open source maintainers are facing challenges due to the influx of AI-generated submissions. The pause affects the workflow and efficiency of these programs, potentially delaying the discovery and resolution of actual vulnerabilities. Researchers and maintainers should adapt their strategies to navigate the new landscape of AI-generated submissions.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,549 builders reading daily.