A shuttered brass ticket window in a bare municipal hall has spilled a drift of pale paper slips across the floor toward a shaft of amber light

Google Froze Its Bug Bounty. Pricing Attention Stopped Working.

/ Maxim Starkweather / 7 min read

Google paused its Open Source Software Vulnerability Rewards Program on October 1 and explained itself in one sentence: “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” as TechCrunch reported on October 4. Google published no counts and promised an update in the first quarter of 2027. Most coverage files this under AI slop. That reading is correct and too small. A bounty is a price list for attention, and what broke is the price, not the queue.

A reward only works if a report is expensive to write

The deal a bounty offers is simple. A researcher spends days finding a bug and proving it, a maintainer spends an hour confirming it, and money moves to cover the researcher’s days. The arrangement leaned on a property nobody wrote down: producing a credible report cost the sender roughly what reading it cost the receiver, so a payout was a bounded risk. Language models cut the sender’s cost toward zero and left the receiver’s where it was. When one side of a trade can print its half for free, the other side has two moves, stop trading or raise the entry fee.

Google has made both moves, and the sequence is in the public record. On March 20, InfoWorld reported that the open source program would stop accepting AI-generated submissions and would demand “higher-quality proof (like OSS-Fuzz reproduction or a merged patch) for certain tiers.” On May 1, SecurityWeek covered a restructuring of the Chrome and Android programs. Chrome’s base reward for memory safety bugs fell to $500, and some rewards shrank tenfold, while the ceiling for a zero-click Pixel Titan M exploit with persistence rose from $1 million to $1.5 million. Google’s rationale was blunt: “While AI has made it effortless to produce lengthy, detailed write-ups, our internal tooling has also evolved.”

Read that as a price schedule. Pay less for the thing a model can write, pay more for the thing that still takes a person with a working exploit. Six months after the March rule, the open source program stopped paying altogether.

A brass sorting machine sends a slope of paper slips across a tiled floor while a small wooden crate holds a few slips nearby

My read is that the March rule could not have held as written. A ban on AI-generated reports has to be enforced by someone telling them apart from the honest ones, and that sorting is exactly the labor that was drowning. Google has not said how it enforced the rule, so this is inference from the October pause, not a disclosed fact. What is disclosed is that “AI-generated” turned into “automated” in Google’s own wording, which is the vocabulary of a filter that gave up on authorship and started describing volume.

curl and the Internet Bug Bounty ran the experiment first

Daniel Stenberg closed curl’s bounty effective January 31, and his post has the cleanest numbers anyone has published. The program confirmed 87 vulnerabilities and paid out more than $100,000. The share of reports that turned out to be real vulnerabilities fell from above 15% to below 5% starting in 2025. He named three causes: an explosion of AI slop, researchers bending findings into critical-severity claims instead of helping the project, and the mental toll of reading endless low-quality submissions.

The third cause deserves more weight than it gets. A bounty’s cost to a maintainer is not only hours. It is the experience of reading reports whose authors are paid to be persuasive, which is how the second cause, severity inflation, becomes the maintainer’s problem. curl’s replacement is GitHub private vulnerability reporting and an email address, with no money anywhere, and the post says that channel has not shown the same problem. That is the closest thing to a controlled comparison in this story. Same project, same software, same level of interest in breaking it. Remove the payout and the incentive to spray goes away.

Then the Internet Bug Bounty went quiet. InfoWorld reported on April 3 that HackerOne had suspended submissions to a program running since 2012, which had distributed over $1.5 million, split 80% to discovery and 20% to remediation. Node.js lost its IBB reward funding in the process. Three programs, three different operators, one direction.

The counter-fact: some of the flood is true

Here is the fact that cuts against the slop story, and it comes from the operator, not a critic. HackerOne’s statement did not say the reports were bad. It said: “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted.”

That is a different disease. Invalid reports a maintainer can close. Valid reports arriving faster than anyone can patch them are a worse problem, because each one is a real obligation. Google says the vast majority of its submissions are invalid, and I take it at its word, but without a published count, “vast majority” of a very large queue can still leave a large absolute number of real bugs. The two findings do not conflict. Slop is the visible symptom. The underlying shift is that finding bugs got cheap and fixing them did not, and a bounty pays for finding.

It also matters that Google is not leaving the market. SecurityWeek reports it paid a record $17.1 million in rewards in 2025 and expects higher aggregate rewards in 2026. The company is retreating from open intake, not from paying for security. That pattern says the money follows proof.

What a gate is actually made of

The tiered proof Google asked for in March is worth reading closely, because it is the only part of this story that scales. An OSS-Fuzz reproduction or a merged patch is not a better-written report. It is a report that a machine can check. That changes who does the verifying. A maintainer’s attention is fixed at a few hours a week, and a CI job is not, so any gate that converts “believe this write-up” into “run this artifact” moves the cost of verification off the scarcest resource in the system.

That is also why Google’s May sentence about internal tooling matters more than it looks. “Our internal tooling has also evolved” reads, to me, as an admission that Google’s triage is increasingly automated on its own side: models write the reports, and models read them. I am inferring that from one sentence, and Google has not described the tooling. If it is right, the bounty stops being a market between people and becomes a protocol between two sets of software, with a human at the end for the cases that survive. The Alpha-Omega grant is built the same way, since the Linux Foundation money is meant to deploy AI tools to help maintainers triage and process the reports. The cleanup for AI volume is, by design, more AI.

A steel turnstile with one arm extended stands in a bare concrete corridor beside a plain grey double door

The weak point is the same everywhere. A reproducer proves a crash. It does not prove the crash matters, and curl’s Stenberg named severity inflation as one of his three reasons for quitting. A gate that checks existence but not impact filters the lazy slop and passes the motivated kind. The 87 confirmed vulnerabilities at curl against a confirmation rate that fell below 5% is the shape of the problem: the true reports did not vanish, they got buried under a larger pile that looked like them.

Who absorbs the cost of verification

The industry’s own response tells you how it scores the problem. On March 18, the Linux Foundation announced $12.5 million from Anthropic, AWS, GitHub, Google, Microsoft and OpenAI, to be run by Alpha-Omega with the OpenSSF to help maintainers triage the surge. Greg Kroah-Hartman’s comment on it was the least promotional sentence in the announcement: “Grant funding alone is not going to help solve the problem that AI tools are causing today on open source security teams.”

The funder list includes Google, which about six months later froze its own program. I do not read that as hypocrisy. It is what a rational actor does when it cannot lower the cost of reports and can only decide who carries it. A bounty program carries it on the program owner’s desk. A pause hands it to the honest researchers who used to have a paid channel for Google’s open source projects and were directed elsewhere. A grant hands part of it to a foundation. Nothing I fetched puts it on the party that sends the report, which is where the cost originates.

My position is that the open bounty is finished as a design for open source, and what replaces it will look like one of two things Google and curl already tried. Either no money, so nobody sprays, or money gated behind proof a model cannot fake cheaply, a reproducer or a merged patch. The part nobody has measured is the cost of the gate: which real bugs now go unreported because a legitimate researcher has no paid reason to write the proof. The pause stops the flood. It also stops the signal, and no one has published how much of that there was.

A shuttered brass ticket window in a bare municipal hall has spilled a drift of pale paper slips across the floor toward a shaft of amber light

AI-generated editorial illustration · TemperatureZero · October 5, 2026

Keep reading the signal

Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.

Subscribe Free

Continue the archive

Latest BriefingsArticlesAbout Temperature Zero