Hit by TechCrunch: Google has paused its open-source software vulnerability bounty program (OSS VRP), effective October 1, and said it will provide an update in Q1 2027.

The official reason is straightforward: automated submission volumes have surged, and “most of them do not hold up.” According to Tom's Hardware, Google engineers and open-source maintainers have been flooded with a large number of invalid reports—some even fueled by AI hallucinations. For now, participants can only switch to Google’s other bounty programs.

AI can help white hats find bugs, but it can also mass-produce junk reports, overwhelming reviewers. Many protocols in the crypto space also rely on bounties for security—this noise problem will likely show up in their cases sooner or later.

#AI #Google #漏洞赏金