Google has paused its Open Source Software Vulnerability Rewards Program after automated vulnerability reports rose sharply and most proved invalid. The program paid researchers for finding security flaws in Google’s open-source projects.

The suspension took effect October 1. Google says it will provide an update in the first quarter of 2027 and is directing researchers to its other bug-bounty programs in the meantime. According to TechCrunch, engineers and maintainers were dealing with reports that contained hallucinated findings or otherwise failed validation.

AI tools can scan more code and draft reports quickly, but cheap generation changes the economics of a bounty queue. A plausible-looking submission still consumes expert time to reproduce, classify and reject. When low-quality volume grows faster than review capacity, valid discoveries can take longer to reach the people able to fix them.

The pause does not show that AI-assisted security research is inherently useless. It shows that programs need stronger evidence requirements and automated intake controls when submission costs collapse. Reproducible test cases, affected versions, minimal proofs of concept and rate limits could help distinguish findings from generated speculation. Google has not yet described the revised rules it may use when this particular program returns.