Why Google Froze Its OSS Bug Bounty Over AI Slop (2026)
The short answer
Google stopped accepting product vulnerability reports to its Open Source Software VRP on October 1, 2026 because AI-generated hallucinated reports were burying maintainers; the same week System76’s COSMIC desktop became the first major Linux desktop to ban LLM-generated pull requests outright. Neither move is anti-AI. Both are the receiving end of the pipeline refusing to be the free verification layer for unverified machine output. Google will update on the program by Q1 2027. Facts verified October 4, 2026.
What Google changed
| Before Oct 1, 2026 | After Oct 1, 2026 | |
|---|---|---|
| Product vulnerabilities in OSS VRP-scope projects | Accepted, rewarded | Suspended |
| Supply-chain reports (build pipelines, tampered packages) | Accepted | Accepted — unchanged |
| Reports filed before Oct 1 | — | Still processed |
| Product bugs in some Google Cloud repos | OSS VRP or Cloud VRP | Cloud VRP only |
| Next update | — | By Q1 2027 |
Google announced the change on X the day it took effect. Its stated reason: “an influx of invalid AI-driven reports.” Reports that claimed to find bugs turned out to be hallucinations or ordinary coding errors with no security impact, and engineers and maintainers were spending their time validating code instead of fixing real, critical vulnerabilities.
The OSS VRP launched in 2022 to pay for flaws in Google-maintained open-source projects (Bazel, Angular, Golang, Protocol Buffers, Fuchsia and others). It is a small program next to Google’s main VRP — which is exactly why it cracked first: a flood that a large triage team could absorb overwhelms a small one.
What COSMIC changed
COSMIC’s pull request template now requires contributors to certify that the PR contains no LLM-generated content — source code, comments or PR description — alongside the existing confirmations that they understand their change, can respond to review, have tested it, and sign the Developer Certificate of Origin. Missing certification can get the PR closed.
Jeremy Soller of System76 framed it as a workload decision: maintainers saw more first-time contributors submitting LLM-written PRs that were “unplanned and rarely accepted,” each one still needing a careful review. In August 2026 contributor Jacob Gkau had already said most large LLM-written PRs were being rejected on copyright and maintainability grounds. The policy had required disclosure; it now requires absence. Two carve-outs: non-generative AI (bug finding, static analysis) is fine, and cosmic-flatpak is exempt because upstream projects own their own manifests and COSMIC only checks sandboxing.
Why both happened in the same week
The common cause is asymmetric cost. Generating a plausible bug report or PR with a frontier model costs cents and seconds. Verifying it costs a maintainer’s hour. When the generation side scales and the verification side does not, the only moves available to the receiving side are to raise the bar (require working exploits, human certification) or close the door (suspend intake). Google did the second temporarily; COSMIC did the first permanently.
This is not new — curl’s Daniel Stenberg has been publicly documenting AI-slop security reports since 2024, and the Linux kernel and Intel have dealt with the same wave — but October 2026 is the first time a hyperscaler’s bounty program suspended a category because of it.
The uncomfortable part: AI finds real bugs too
The week Google froze OSS VRP, Horizon3’s Zach Hanley used Anthropic’s Mythos to find CVE-2026-61500 in Rejetto HTTP File Server: session-cookie signing keys derived from Math.random(), letting attackers forge admin sessions for full RCE. Within 24 hours of disclosure a China-based actor was exploiting it against US hosts. That is the second Anthropic-linked vulnerability known to be exploited in the wild.
So the signal is real and the noise is real. The difference between Hanley’s report and the ones Google is rejecting is not the tool — it is that a human verified the finding, wrote a working exploit and put their name on it. That is the standard bounty programs are converging on.
What this means for you
- Submitting to bounty programs: include a working proof of concept and reproduction steps, disclose AI assistance, and expect programs to require both. Hallucinated reports now cost you reputation, not just a rejection.
- Running an open-source project: copy COSMIC’s template if review load is the problem, or require disclosure plus a reproduction if you want AI-assisted PRs but not drive-by ones. Decide before the flood.
- Running a bounty program: OSS VRP’s suspension is the warning. Build the verification bar into intake (PoC required, rate limits per reporter, AI-assistance disclosure) rather than discovering the limit when triage collapses.
Related: Reddit’s AI slop crackdown, what is knowledge distillation — legitimate vs malicious, CVE-2026-90970 GitLab AI Gateway explained.
Last verified: October 4, 2026.