MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via The Hacker News

Google Halts Open-Source Bug Bounty Program Over Flood of Low-Quality Automated Submissions

Image via The Hacker News
Image via The Hacker News

Google has suspended its bug bounty program for open-source projects including Go, Angular, and Protocol Buffers effective October 1, citing an influx of invalid automated vulnerability reports. The pause prevents researchers from submitting security findings for compensation, though reports regarding supply chain compromises continue to be accepted. Prior submissions filed before the deadline remain eligible for rewards, limiting the immediate impact to future vulnerability disclosures.

Expanded Detail

Google's decision to temporarily close its vulnerability reward initiative for several prominent open-source libraries represents a significant shift in how the technology giant manages security research contributions. The move stems from a documented surge in submissions that lack legitimacy, suggesting that automation tools have been deployed to generate bulk reports rather than genuine security discoveries. This suspension creates a gap in the formal incentive structure that typically encourages qualified researchers to identify and report weaknesses.

The timing and scope of the halt warrant attention within the developer community. While historical submissions remain eligible for compensation and critical supply chain vulnerabilities can still be reported through alternative channels, the window for new disclosures has closed indefinitely. This distinction suggests Google is attempting to preserve continuity for actively exploited threats while implementing quality controls to reduce fraudulent activity.

Context

The suspension could affect independent security researchers who rely on bug bounty income, particularly those in regions with limited alternative funding for security work. Open-source projects may experience delayed vulnerability identification during the pause, though the risk may be offset by reduced processing burden on Google's review teams. Developers and organizations dependent on the affected libraries might adjust their internal security monitoring practices, while automation-heavy submissions may redirect toward other programs, potentially creating similar challenges across the broader bug bounty ecosystem.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
AI Agents Force Security and Privacy Recalibration Across Platforms · Artificial intelligence
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports.” Browse more stories.