AI news · October 5, 2026

Google pauses open-source bug bounty after surge in AI reports

securityopen-sourceagents

Made With Models illustration for this story

Google paused its open-source vulnerability rewards program on October 1 after a rise in automated reports. TechCrunch said Google promised an update in the first quarter of 2027, while engineers and maintainers faced invalid or hallucinated findings. Participants were directed to other Google bounty programs.

For builders, the story is a reminder that AI-assisted security testing can create load before it creates value. A cheap stream of plausible-looking reports can slow the maintainers who must review them, and it can reduce trust in legitimate reports if triage becomes noisy.

If you use an agent for vulnerability research, add scope, evidence and duplicate checks before sending a report. Watch for the replacement process Google uses when the program reopens, and measure accepted findings rather than the number of submissions.

Source: TechCrunch ↗ — Made With Models writes the brief; the reporting is theirs.