Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has quietly closed a door that many open-source security researchers relied on. As of October 1, the company is no longer accepting product vulnerability reports for its open-source software through its bug bounty program. The move, first reported by The Hacker News, affects projects such as Go, Angular, and Protocol Buffers — codebases that have historically been popular targets for bounty hunters.

According to Google, the decision was driven by a flood of low-quality, machine-generated submissions. The program was being overwhelmed by invalid automated reports, making it harder for the security team to focus on genuine vulnerabilities. Rather than continue paying out for noise, Google has paused rewards for OSS product bugs entirely.

What Exactly Changed

The pause applies specifically to product vulnerability reports filed against Google-owned open-source projects. Researchers who find a flaw in the code of Go, Angular, Protocol Buffers, or similar projects can no longer submit it to Google's bug bounty program and expect a reward.

Crucially, the change does not shut down all reporting paths. Google continues to accept reports about supply chain compromises — a recognition that attacks targeting the software supply chain remain a serious and distinct threat. Reports submitted before October 1 are still being processed under the old rules.

For many in the community, the distinction matters. A vulnerability in a library is one thing; a compromised build pipeline, a malicious dependency, or a hijacked maintainer account is another. Google appears to be preserving the channel for the latter while closing the former.

Why Google Hit Pause

The root cause is a familiar one in modern bug bounty programs: automation. Large language models and automated fuzzing tools have made it trivially easy to generate plausible-looking vulnerability reports at scale. Many of these reports turn out to be false positives, duplicates, or outright nonsense.

For a company like Google, which runs one of the largest and most visible bounty programs in the world, the cost is not just financial. Every invalid report consumes triage time, engineering attention, and emotional energy from the security team. When the volume of automated junk rises high enough, the signal-to-noise ratio collapses.

Google is not alone in facing this problem. Other major vendors have grappled with similar surges, and some have responded by tightening submission requirements, requiring proof-of-concept exploits, or restricting which assets are eligible. Google's approach here is more drastic: a full pause on a category of reports.

What It Means for Researchers

For independent researchers and bug bounty hunters, the immediate impact is a loss of a payout channel. Open-source projects like Go and Angular are widely deployed, and finding a serious vulnerability in them could previously earn a meaningful reward. That incentive is now gone — at least temporarily.

Some researchers may redirect their efforts to other programs, while others may continue reporting flaws through non-bounty channels, such as project-specific security policies or public issue trackers. However, without a financial incentive, the volume of high-quality reports may decline.

There is also a broader concern: if Google is not rewarding OSS product bugs, will fewer researchers look at these codebases at all? The answer likely depends on how the pause is communicated and how long it lasts. Google has not indicated a timeline for resuming rewards.

A Growing Tension in Bug Bounties

The pause highlights a structural tension in the bug bounty model. Bounties were designed to incentivize human creativity and deep analysis. Automated tooling can assist that work, but when it is used to spray reports indiscriminately, the model breaks down.

Companies are now experimenting with ways to filter out automated noise. Some require detailed reproduction steps. Others use reputation systems, invite-only tiers, or manual review gates. Google's pause is a blunt instrument, but it may serve as a pressure-release valve while the company rethinks its approach.

For the security community, the episode is a reminder that bug bounty programs are not public utilities. They are discretionary programs run by vendors, and their terms can change. Researchers who depend on them should diversify their sources of income and engagement.

What Comes Next

Google has not said whether the pause is permanent or temporary. The company may use the time to build better filtering, adjust reward structures, or redefine which OSS reports are eligible. In the meantime, supply chain reports remain open, signaling that Google still values external eyes on its most critical dependencies.

For now, researchers looking to report a bug in Go, Angular, or Protocol Buffers will need to find another route. And the broader industry will be watching to see whether other vendors follow Google's lead — or find a smarter way to separate signal from noise.

Source: The Hacker News