Google has announced that it is temporarily pausing the Open Source Software Vulnerability Rewards Program, which rewards the discovery of security vulnerabilities in open source software. The reason for the decision is the significant surge in reports generated automatically with AI tools, the vast majority of which are invalid; these reports create an additional burden on engineers, and some contain inaccurate information and hallucinations. The acceptance of new submissions ended as of October 1. While the company did not provide a definitive restart date, it announced that it would share an update on the program’s future in the first quarter of 2027. During this period, researchers are being directed to Google’s other bug bounty programs.
Background
Google is not a new name in the FikirPilot archive: we have published 81 stories featuring this name in the last 90 days; the most recent is dated October 7, 2026.