Google Halts Open Source Bug Bounty, AI Blamed as the Culprit
Baca dalam 60 detik
- Google menghentikan sementara program hadiah untuk celah keamanan perangkat lunak open source per 1 Oktober akibat lonjakan kiriman otomatis berbasis AI.
- Mayoritas laporan yang masuk tidak valid atau mengandung halusinasi, membuat engineer dan pengelola proyek kewalahan.
- Peninjauan ulang program dijadwalkan pada kuartal pertama 2027, sementara peserta diarahkan ke skema bounty lain milik Google.

Google has officially suspended its Open Source Software Vulnerability Rewards Program (OSS VRP) starting October 1, 2025. The decision was made after the company recorded a significant surge in automated submissions that were mostly invalid. The program, which had served as a channel for security researchers to report vulnerabilities in Google's open source software, will be evaluated and rescheduled in the first quarter of 2027.
This move marks the first time the tech giant has halted a bounty program that had been running for a long time. In an announcement on platform X and the program's official site, Google stated that the suspension was necessary because the volume of incoming submissions far exceeded verification capacity. According to a Tom's Hardware report, Google engineers and open source project maintainers were overwhelmed by a flood of inaccurate reports, many of which were the product of AI model hallucinations.
This phenomenon is not new in the cybersecurity industry. Since last year, experts have warned that the use of generative AI to produce vulnerability reports could damage the bug bounty ecosystem. AI-generated reports often appear syntactically convincing but lack a strong technical basis. As a result, security teams must allocate extra time to verify each report, which in turn erodes productivity.
"This suspension is due to a significant surge in automated submissions, the majority of which are invalid," Google wrote in its official announcement.
The impact of this decision is not felt by Google alone. Other open source bug bounty programs, such as those managed by nonprofit organizations or other technology companies, face similar challenges. Without an effective filtering mechanism, the wave of AI reports could threaten the sustainability of programs that are the backbone of global software security.
For Indonesia, this development is an important reminder. The country's open source ecosystem, which is growing with the emergence of various local projects and developer communities, needs to anticipate similar risks. Without a layered verification system and strict reporting guidelines, local bounty programs could meet the same fate. In addition, the adoption of AI in the vulnerability reporting process must be balanced with adequate security literacy so as not to create new problems.
Going forward, Google promises to provide an update in the first quarter of 2027. However, until then, security researchers are urged to shift their attention to other bounty programs that are still running. The question is, will the industry be able to create a solution that separates quality reports from AI junk? If not, it is not impossible that similar programs around the world will follow suit and be suspended.



