metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
Cybersecurity
Bug Bounty
Open Source
AI Security
Google

Google Suspends OSS VRP Bug Reports Over AI Slop

Google suspended product vulnerability reports to its OSS VRP on October 1, 2026 after a flood of invalid AI submissions. What it says about bug bounty economics.

Metir AI TeamOctober 4, 20265 min read
Google Suspends OSS VRP Bug Reports Over AI Slop

Google stopped accepting product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP) on October 1, 2026, citing an influx of invalid AI-driven reports. Tom's Hardware reported the freeze, and Google says it will share an update on the program's future by the first quarter of 2027. The OSS VRP suspension is the clearest sign yet that bug bounties are being strained by a simple change: writing a plausible vulnerability report now costs almost nothing.

Oct 1, 2026OSS VRP product reports suspendedpre-October reports still processed
Q1 2027Google's promised program update
Under 5%curl reports confirmed as real in 2025down from over 15% in prior years
$9,250 to $2,257Internet Bug Bounty critical payoutcut May 18, 2026

What the Google OSS VRP suspension covers

According to reporting on the announcement, the pause applies to product vulnerabilities in open-source projects. Reports submitted before October 1 are unaffected, and so are OSS VRP supply chain submissions. For some Google Cloud repositories, product bugs may still be accepted through the Cloud VRP. Researchers were encouraged to explore other Google VRP programs while the pause lasts. The program's own rules live on Google's Bug Hunters site.

The freeze was not Google's first move. Earlier in 2026, per InfoWorld, Google restricted AI-generated reports and rewrote the OSS VRP rules to filter low-quality submissions and weight real-world impact. A full suspension suggests the rule changes did not reduce the review burden enough.

A pattern across programs, not a Google quirk

Several projects reached similar conclusions over the past nine months.

Programs that pulled back in 2026

Each change targets the same bottleneck: the human time needed to verify a report.

Feb 1
curl stops taking reports on HackerOne
Announced in January; reports move to GitHub. Roughly 95% of the project's HackerOne reports since 2025 were invalid.
Mar 2026
Google rewrites OSS VRP rules
A first attempt to filter low-quality reports and weight real-world impact.
Mar 27
Internet Bug Bounty pauses submissions
HackerOne says AI-assisted research has shifted the balance between findings and remediation capacity.
May 18
Internet Bug Bounty cuts rewards
Critical payouts fall from $9,250 to $2,257, a 76% reduction.
Oct 1
Google suspends OSS VRP product reports
Supply chain reports are unaffected; an update is promised by Q1 2027.
Oct 2026
System76 COSMIC bans LLM-generated pull requests
Contributors must certify that code, comments and descriptions contain no LLM output.

Source: reporting from Hackaday, InfoWorld, The Register, Tom's Hardware and Linuxiac (see Sources below).

  • curl announced in January that it would stop accepting reports through HackerOne from February 1. The Register reported that the share of submissions confirmed as vulnerabilities had run above 15 percent for years before falling below 5 percent in 2025, and Hackaday described many submissions as lengthy text an LLM produced in seconds but that takes a human far longer to check.
  • The Internet Bug Bounty paused submissions in late March, with HackerOne saying AI-assisted research was expanding discovery faster than open-source maintainers could remediate. The Register later reported payout cuts from May 18: critical findings fell from $9,250 to $2,257 and medium findings from $1,843 to $297.
  • System76's COSMIC desktop now requires contributors to certify that pull requests contain no LLM-generated code, comments or descriptions. Linuxiac quotes Jeremy Soller saying maintainers saw more first-time submissions using LLMs that were unplanned and rarely accepted. The aim, per reports, is a manageable review load rather than opposition to AI tools.

The economics: cheap to submit, expensive to verify

A bounty program is a market with two costs. The submitter pays to find and write up a bug. The program pays to triage it. For years those costs were loosely matched, because producing a convincing report took real effort.

Language models broke that match on the supply side only. As researcher Jakub Ciolek put it in The Register's coverage, finding plausible bugs is becoming much cheaper, while the expensive part is still very human: someone has to verify impact, deduplicate reports and decide whether something crosses a security boundary.

When submission cost approaches zero, even a very low hit rate has positive expected value for the sender, so volume rises regardless of quality. The validator's cost per report does not fall, so the signal-to-noise ratio decides whether the program is affordable. Reward cuts, like the Internet Bug Bounty's, punish honest researchers as much as spammers, which is why Ciolek warned that serious researchers will price changing rules in as risk or stop participating.

“

Finding plausible bugs is becoming much cheaper. The expensive part is still very human.

Jakub Ciolek, via The Register

The paradox: AI also finds real bugs, fast

Blocking AI outright is not a clean answer, because the same tools find genuine flaws. The Register reported that curl's Daniel Stenberg saw a shift from low-quality AI reports to really good security reports, almost all done with the help of AI.

The speed cuts both ways. On September 30, Horizon3 disclosed CVE-2026-61500, an authentication bypass in Rejetto HFS found with Anthropic's Mythos model. Per AI Weekly's summary of The Register's coverage, VulnCheck canaries saw an attacker targeting vulnerable hosts within a day. That matches the broader finding in Microsoft's Digital Defense Report 2026 that the median time to weaponization is now under 24 hours.

Portrait of Daniel Stenberg, founder and lead developer of curl
Daniel Stenberg, curl's founder and lead developer (portrait taken in 2015). Curl ended its HackerOne bounty in February 2026 after a surge of invalid reports. Photo by Daniel Stenberg, CC BY 4.0.

What maintainers and programs are trying

The levers visible so far are about moving verification cost back to the submitter:

  • Proof requirements. Reports that must include a working reproduction are expensive to fake. The Mesa project, per Hackaday, introduced code comprehension requirements for submitters.
  • Moving the channel. curl shifted to GitHub reports, removing the cash incentive that attracted volume.
  • Contribution certification. COSMIC's pull request attestation makes a submitter accountable for understanding what they send.
  • Reweighting rewards. HackerOne said 80 percent of Internet Bug Bounty payouts had gone to new discoveries and 20 percent to remediation, a balance InfoWorld reported it no longer considers right.

Reputation gating, where only submitters with a track record reach a human, is another logical option, though the sources here do not show a program adopting it for this problem.

What to watch

Google's Q1 2027 update will show whether a major vendor restores open submissions with stricter gates or keeps product reports closed. The underlying tension will remain: defenders need AI to find bugs at attacker speed, while every program needs a way to tell a verified finding from a fluent guess. The scarce resource is no longer discovery. It is trustworthy verification and remediation capacity.

Sources:

  • Google freezes open-source bug bounty program amid flood of invalid AI slop submissions | Tom's Hardware
  • Google Freezes OSS VRP Product Bug Reports After AI Slop Flood | AI Weekly
  • Google Open Source Software Vulnerability Reward Program Rules | Google Bug Hunters
  • Streamlining Google's OSS VRP: Key Rule Updates | Google Bug Hunters
  • Internet Bug Bounty program hits pause on payouts | InfoWorld
  • HackerOne takes an axe to its bug bounty rewards | The Register
  • Curl shutters bug bounty program to stop AI slop | The Register
  • The curl project drops bug bounties due to AI slop | Hackaday
  • COSMIC Stops Accepting LLM-Generated Content in Pull Requests | Linuxiac
  • Anthropic Mythos Finds Rejetto HFS RCE | Horizon3.ai
  • Anthropic's Mythos finds Rejetto HFS flaw, exploited in a day | AI Weekly

Image credits

  • Hero: Google headquarters building at the Googleplex, Mountain View, California. Wikimedia Commons, photographed July 27, 2016 by Asoundd, licensed CC BY-SA 4.0.
  • Portrait of Daniel Stenberg, curl founder, photographed October 13, 2015 by Daniel Stenberg. Wikimedia Commons, licensed CC BY 4.0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational