A bounty programme that stopped taking reports

Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program, and the reason it gives is the volume of machine-written submissions arriving at the programme. The pause took effect on 1 October 2026. Google has not named a date to reopen, saying instead that it will provide an update in the first quarter of 2027.

The company attributed the decision to “a significant rise in automated submissions, the vast majority of which are not valid”, according to the programme notice reported by Help Net Security. The programme covers vulnerabilities in Google’s own open-source software, including projects such as Go, Angular and Protocol Buffers, which sit underneath a large amount of software that Google does not control.

This is a bounty programme declining to be paid to look. That is the part worth sitting with: the bottleneck is no longer the supply of people willing to hunt for flaws, it is the capacity of the engineers who have to read what comes in.

Printed paper documents and receipts spread across a white desk
Reports filed before 1 October will still be processed. Illustrative photograph. https://kaboompics.com/ · pexels · Pexels License

What is still in scope

The suspension is narrower than a shutdown. Reports filed before 1 October are unaffected and will still be processed. Supply chain reports to the same programme — the category covering how Google’s open-source code is built and distributed rather than what the code itself does wrong — continue to be accepted. Some product vulnerabilities affecting Google Cloud repositories can still be submitted through the separate Cloud Vulnerability Reward Program, according to the reporting.

Researchers who find something in the meantime are being pointed at Google’s Patch Rewards Program, which pays for security improvements rather than for the discovery of a specific flaw. That is a different proposition. A patch reward asks a researcher to do the engineering work as well as the finding, which filters out exactly the submissions Google says are swamping it — but it also raises the bar for the people who were doing the work properly.

A complaint the wider ecosystem has been making

Google is not the first maintainer to say this out loud. The pattern — long, confident, fluent reports describing vulnerabilities that do not exist — has been reported across open-source projects for roughly two years, with the curl project and the Linux Foundation among those describing the same drain on reviewer time. What is new is the size of the organisation acting on it, and the bluntness of the remedy.

The economics are unforgiving. A plausible-looking vulnerability report now costs almost nothing to generate and still costs a human engineer real time to disprove. Every programme that pays per valid finding is exposed to that asymmetry, and a programme that cannot triage faster than reports arrive has only two options: hire, or close the door.

A laptop screen showing lines of program source code
The programme covers Google open-source projects including Go, Angular and Protocol Buffers. Illustrative photograph. Daniil Komov · pexels · Pexels License

What this costs

The cost is not obvious from the outside, because nothing breaks. Google’s open-source projects do not become less secure the day the form stops accepting submissions. What changes is the rate at which genuine flaws are found by people outside the company, in code that thousands of other organisations depend on and that few of them audit themselves.

The thing to watch is whether the promised first-quarter 2027 update reopens the programme with a filter, a fee, a reputation requirement, or something else. Bug bounties were built on the assumption that submissions were expensive to produce and cheap to check. That assumption has now been inverted, and Google is the largest operator to concede the point in public.