On October 1, Google stopped paying for vulnerability reports in Go, Angular, Flutter, Bazel, Protocol Buffers and every other project in its Open Source Software Vulnerability Reward Program. Google blames a rise in automated submissions, "the vast majority of which are not valid." The company calls the pause temporary and says it will post an update in the first quarter of 2027. That is at least three months with no bounty on the toolchain a large share of the industry builds on.
The details come from The Hacker News and the program's rules page. Product vulnerability reports are closed for the 26 flagship repositories and the 47 repositories in the important tier. Flagship bugs paid between $500 and $7,500. Bugs in the important tier paid between $101 and $3,133.70. Both numbers are now zero until further notice.
Some of the program survives. Google is still taking:
- Supply chain compromise reports, which pay $500 to $31,337. That covers things like a poisoned build pipeline or a leaked signing key.
- Other security issues such as leaked credentials in a repository.
- Anything filed before October 1, which will be triaged and paid under the old rules.
- Patches through the Patch Rewards Program, which pays $100 to $15,000 for an accepted fix.
If you find a real bug in Go today, the path is the project's own channel at security@golang.org, with no money attached. Google Cloud repositories can still go through the Cloud VRP. Google has not published any numbers on how many automated reports it received or what fraction were junk. "The vast majority" is the only figure on offer.
The Go team said this a month ago
The Go project added a section titled "LLM-Generated Reports" to its security policy in September. It is short, and it is the most honest statement any large project has made about the problem. The opening line is "Please do not send LLM-generated reports without proper curation." Then this:
Modern LLMs are very good at finding real and important security bugs. Unfortunately, they are also very good at finding imaginary issues, or real issues that are not security bugs. LLM output is often verbose, buries important information in irrelevant text, and contains grandiose and unsupportable claims.
The policy goes on to say that the value of a report a model produced "lies in curation," and that a reporter who forwards dozens of candidate findings and expects the Go team to sort them is asking the team to do the reporter's job. Go now withholds credit from anyone whose submissions are mostly rejected and who shows no sign of filtering. They declined to define a threshold. The intent is clear enough without one.
Read those two paragraphs together and the Google pause makes more sense. The models are finding bugs. The Go team says so in writing. The failure is in the pipeline between the model and the maintainer, where a person is supposed to read the output, reproduce it, and throw away the nine out of ten that don't hold up. When a bounty is on the table, that person has every incentive to skip the filtering step and submit everything.
curl went first, with numbers
Daniel Stenberg shut down curl's HackerOne bounty on January 31, 2026, after nearly seven years, 87 confirmed vulnerabilities, and more than $100,000 paid out. The Register covered the announcement. Stenberg's goal was to "remove the incentive for people to submit crap and non-well researched reports." By his estimate, around 20 percent of submissions came from AI tools by mid 2025. The rate of confirmed vulnerabilities had been about 15 percent for most of the program's life. In 2025 it fell under 5 percent. Not one in twenty was real.
curl kept HackerOne as an intake form with no payment attached starting March 1. Then from July 1 through August 3 the project stopped accepting vulnerability reports through any channel at all, for a month, so the security team could rest. A project with curl's install base went dark on security intake for five weeks and nothing happened. That tells you how much signal was in the queue.
Intel ended its bounties on Intigriti for the same reason, according to Malwarebytes. Google is the third large program to pull money off the table in nine months, and by far the biggest.
Google's May answer was to pay more for what models can't find
Google reacted to automated submissions once already this year. On May 5, the company rewrote its Android and Chrome programs. Help Net Security has the numbers. The top Android reward went to $1.5 million for a zero-click exploit chain against a Pixel that persists through Titan M2. A full exploit chain in Chrome pays up to $250,000. At the same time Google cut the bonuses for renderer remote code execution and arbitrary read/write bugs, and deprioritized Linux kernel findings unless the reporter shows they are exploitable on an Android device.
Google's stated reasoning in May was to emphasize "categories that remain more challenging for automated AI tooling to find." That is the same strategy as the October pause, applied with a scalpel instead of a hatchet. Raise the price on the bugs that need a human with a debugger and a week of patience. Cut the price to zero on the bugs a model can pattern match from a diff. The Android and Chrome programs could do that because exploit chains are hard to fake. An open-source library with 47 repositories in the important tier can't be sliced the same way, so Google closed the whole thing.
Bounties pay for the claim, not the fix
I maintain an open-source backup server. I have never run a bounty on it and I never will, and this year is the reason. Triage is the expensive part of security work. Someone has to read the report, build the version named in it, write a reproduction, and decide whether the thing described is a vulnerability, a bug, or a hallucination. For a real finding, that costs an hour or two. For a plausible fake, it costs the same hour or two, and then another hour explaining why it was rejected. A model can produce a plausible fake in under a minute. The economics were always going to break once generation got cheap, and they broke this year.
The bounty model paid for a claim. The Patch Rewards Program pays for a fix. That difference is the whole story. A patch has to compile, pass the tests, and survive review. A claim only has to sound right to a triager who is already behind. Google kept the program that pays for fixes and closed the one that pays for claims, and I think that split will outlast the pause.
For anyone running a program smaller than Google's, the Go policy is the template. Require a reproduction. Track each reporter's hit rate. Stop crediting people whose hit rate is below some number you don't publish. None of that needs money. It needs a policy page and the will to enforce it.
My prediction: the OSS VRP does not come back in its old form. The update due in the first quarter of 2027 will either keep product bugs closed and point people at Patch Rewards, or reopen with an invite list of reporters who have a track record. Open intake with cash attached is finished for Google's open-source projects, and curl's queue going quiet for five weeks in July is the evidence that nobody will miss it.