Google Halts Open-Source Bug Bounty Program Over Flood of Low-Quality Automated Submissions

Google has suspended its bug bounty program for open-source projects including Go, Angular, and Protocol Buffers effective October 1, citing an influx of invalid automated vulnerability reports. The pause prevents researchers from submitting security findings for compensation, though reports regarding supply chain compromises continue to be accepted. Prior submissions filed before the deadline remain eligible for rewards, limiting the immediate impact to future vulnerability disclosures.
Google's decision to temporarily close its vulnerability reward initiative for several prominent open-source libraries represents a significant shift in how the technology giant manages security research contributions. The move stems from a documented surge in submissions that lack legitimacy, suggesting that automation tools have been deployed to generate bulk reports rather than genuine security discoveries. This suspension creates a gap in the formal incentive structure that typically encourages qualified researchers to identify and report weaknesses.
The timing and scope of the halt warrant attention within the developer community. While historical submissions remain eligible for compensation and critical supply chain vulnerabilities can still be reported through alternative channels, the window for new disclosures has closed indefinitely. This distinction suggests Google is attempting to preserve continuity for actively exploited threats while implementing quality controls to reduce fraudulent activity.
The suspension could affect independent security researchers who rely on bug bounty income, particularly those in regions with limited alternative funding for security work. Open-source projects may experience delayed vulnerability identification during the pause, though the risk may be offset by reduced processing burden on Google's review teams. Developers and organizations dependent on the affected libraries might adjust their internal security monitoring practices, while automation-heavy submissions may redirect toward other programs, potentially creating similar challenges across the broader bug bounty ecosystem.