TechRadar News.
Business

Google Pauses Open‑Source Bug Bounty Amid Flood of AI‑Generated Submissions

Google Pauses Open‑Source Bug Bounty Amid Flood of AI‑Generated Submissions

Google said it is putting its open‑source bug bounty program on a temporary pause after detecting a rapid surge in AI‑generated submissions that it says are flooding the system.

According to the firm, the amount of AI‑crafted reports has climbed sharply over the past weeks, putting pressure on its internal triage workflow and complicating analysts’ ability to separate real flaws from low‑quality or repeated entries.

Bug bounty programs that pay outside researchers for finding security weaknesses have become a pillar of contemporary software protection. Google’s open‑source effort, created to safeguard the numerous libraries and frameworks it oversees, has traditionally drawn a varied community of independent security hunters.

The notice explained that the flood of AI‑generated submissions has both swollen the total count and reduced overall trustworthiness. "We are seeing a significant rise in AI‑derived reports that lack the depth and reproducibility needed for effective remediation," the company wrote, noting that the existing process cannot handle the surge without sacrificing quality.

Analysts point out that this pattern mirrors a wider movement: with large language models increasingly reachable, developers and hobbyists are leveraging them to automate the hunt for vulnerabilities. Though this can speed up discovery, it also generates background noise that may obscure genuinely critical problems.

Google did not disclose the duration of the halt, but said it will use the break to improve its intake system, potentially adding automated filters or fresh verification stages to better handle AI‑produced reports.

Cybersecurity specialists warn that this episode highlights the necessity for bounty schemes to adapt as AI advances. "Programs must balance openness with the practical limits of human review," said a cybersecurity analyst who asked to remain anonymous. "Otherwise, the signal-to-noise ratio becomes untenable."

The pause could lead other technology companies to reevaluate their own incentive programs, particularly those that depend heavily on community input. As AI utilities keep maturing, the sector is expected to implement further tweaks designed to maintain the effectiveness of vulnerability‑reporting ecosystems while capitalizing on the rapid pace automation offers.

Source: techcrunch
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related