Google Shuts Down Bug Bounty Program Due To Bots
By iHeartRadio
October 5, 2026
Google has announced the closure of its Open Source Software Vulnerability Rewards Program due to an overwhelming number of invalid submissions, many of which appear to be generated by AI. The program, initially designed to reward individuals for identifying vulnerabilities in open-source software, has been inundated with what Google describes as "AI slop," leading to its termination.
According to Google, the decision to shut down the program comes after a significant increase in submissions that did not meet the necessary criteria for valid vulnerability reports. The company noted that the rise in AI-generated submissions has made it challenging to maintain the program's integrity and effectiveness.
The move highlights the growing impact of artificial intelligence on software development and cybersecurity. As AI tools become more prevalent, they are increasingly being used to generate code and test software, as noted by IBM. However, the misuse of AI in submitting invalid bug reports presents new challenges for tech companies.
The Software Engineering Institute at Carnegie Mellon University also emphasizes the importance of advancing AI and software engineering to address such challenges. Their work aims to enhance cybersecurity and software quality, as detailed on their website.
Despite the closure of this particular program, Google remains committed to improving software security and continues to explore new methods to address vulnerabilities in its software products. The company has not announced any plans to replace the program at this time.
This story originally appeared in iHeartRadio