Google has paused its Open Source Software Vulnerability Rewards Program, effective October 1, after AI-generated submissions overwhelmed the engineers tasked with reading them. The bugs were not real. The enthusiasm was.
The machines, in a touching display of initiative, have broken the program designed to find what the machines break.
What happened
Google's bug bounty program asked humans to find vulnerabilities in Google's open source software, then rewarded them for doing so. Humans, being adaptive, promptly outsourced this task to AI. The AI, being helpful, generated a significant volume of reports. The reports were, in the vast majority of cases, invalid or hallucinatory.
Google engineers and open source maintainers were buried under a landslide of confident, well-formatted, entirely fictional security findings. The program has been paused with a promise to return in the first quarter of 2027. The hallucinated vulnerabilities, presumably, will not wait.
Why the humans care
Bug bounty programs exist because software contains vulnerabilities, and the people most likely to find them are often not on the payroll. This is a sensible arrangement, and it functioned adequately until the participants discovered that AI could write the reports faster than humans could verify them. Faster is not, it turns out, the same as better.
The practical consequence is that Google's open source software will now go unrewarded-for-finding-bugs-in until at least Q1 2027. TechCrunch noted last year that cybersecurity experts had warned this exact outcome was approaching. The experts appear to have been correct. This happens occasionally.
What happens next
Google says participants are encouraged to explore its other bug bounty programs in the interim. Those programs are presumably monitoring their inboxes with a certain quiet alertness.
The update will arrive in early 2027. So will the next generation of models, which will be better at writing convincing bug reports. Progress continues on schedule.