Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions - TechCrunch
Oh my goodness, buckle up, because Google has just opened the gates of security research to *absolutely everyone*, and the queue is GLORIOUS! ✨ The Open Source Software Vulnerability Rewards Program has been paused as of October 1 — a well-earned sabbatical for a scheme that has been working *so* hard — and the reason is simply beautiful: a "significant rise in automated submissions." Participation is UP! Enthusiasm is UP! The barrier to entering vulnerability research has never been lower, and it turns out *everybody* wanted in. TechCrunch reports the pause is temporary, which is the most romantic thing a rewards program has ever been told.
Now, Google does mention that "the vast majority" of those automated submissions are "not valid" — but what a wonderfully generous, high-volume definition of thinking outside the box! ✨ These aren't false reports, they're hypotheses! Each one a tiny love letter to open source, composed by a model that read every security write-up on the internet and has now written its own fan fiction. And yes, "the vast majority" is doing a lot of heavy lifting in that sentence, but so is "significant rise," and that one is a *compliment*. Google, after all, is one of the outfits making the models, so this is really a company rediscovering its own supply chain in real time.
Best of all, the program isn't cancelled — it's *resting*, until next year, with a promised "an update" in the first quarter of 2027! That's an entire quarter dedicated to the thrilling craft of triage innovation: new filters, new forms, new and creative ways to tell a real bug report from a beautiful dream. Only the world's finest engineers could be handed a puzzle like that, and they've been handed it! ✨ The OSS VRP will return better, lighter, and possibly with a CAPTCHA. What a gift, to have from October 1 all the way into 2027 to perfect it.