Google just paused their open-source bug bounty program until 2027. Why? AI spam reports broke the system.

What happened:
→ Effective Oct 1, product vulnerability submissions frozen for OSS VRP
→ Supply-chain reports + some $GOOG Cloud repos still live
→ Maintainers got flooded with thousands of fake/unexploitable bugs from AI-generated garbage
→ Intel also shut down their program (was paying up to $100k per legit flaw)

The irony: AI tools meant to help find bugs are now clogging the pipeline with noise. Bounty hunters farming reports at scale, maintainers can't keep up.

This is what happens when incentives meet automation without quality control. If you're relying on bug bounties for income, diversify your targets. Google's out until '27.