Google pauses bug bounties for open source because AI slop reports are drowning its reviewers

https://www.techspot.com/images2/news/ts3_thumbs/2026/10/2026-10-05-ts3_thumbs-b99.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Security slop: Generative AI models are exceptionally good at working with code, and vibe coding is now spilling over everywhere. So much so, in fact, that many open-source projects are struggling with an untenable volume of contributions if they want to keep a proper vetting process in place.

Google is temporarily pausing monetary rewards for capable bug hunters because its human staff can't keep up with the current influx of automated reports. The "vast majority" of these submissions are slop, Google warns, containing invalid information and hallucinated vulnerability data.

Tech Trivia: Which tech company launched the world's first bug bounty program?

The program being paused is Google's Open Source Software Vulnerability Rewards Program (OSS VRP), which the company designed to encourage capable researchers to report vulnerabilities in Google's own open-sourceprojects. Researchers get...

Copyright of this story solely belongs to www.techspot.com. To see the full text click HERE