Google has suspended its open-source bug bounty program after a flood of AI-generated junk submissions overwhelmed the very security systems that keep the internet's foundational code safe for ordinary users.

The Open Source Software Vulnerability Rewards Program — which paid researchers to find real vulnerabilities in Google's open-source ecosystem — froze as of October 1 and won't reopen until at least the first quarter of 2027. The culprit is AI slop: automated, hallucinated reports that bury legitimate security findings under mountains of garbage. Google admitted as much, stating the pause came from "a significant rise in automated submissions, the vast majority of which are not valid."

This matters because open-source code is the backbone of the internet Americans use every day — from banking to communications to infrastructure. When the bug bounty system that protects that code breaks down, real vulnerabilities go unfixed while engineers waste hours sorting AI hallucinations from actual threats.

Both outlets agree on the core facts. But the framing splits on what matters. TechCrunch noted that cybersecurity experts warned about this exact risk last year — AI slop posing a serious threat to bug bounty programs — making this a predictable disaster Google chose to ignore. The Verge buried the broader infrastructure risk in a single clause noting Linux has been "suffering from a similar problem," without spelling out what that means for the open-source ecosystem as a whole.

According to Tom's Hardware, cited by TechCrunch, Google engineers and open-source maintainers were "overwhelmed by reports that were invalid or contained hallucinations." In other words: AI tools are hallucinating security bugs that don't exist, humans have to manually debunk each one, and the system buckled under the weight.

Google's response? It redirected participants to its other bug bounty programs — as if the same AI slop problem won't simply migrate there next. No structural fix. No plan to filter automated submissions. Just a freeze and a shrug.

The pattern is clear. Big Tech races to ship AI products for the hype cycle while the AI it's already deployed corrodes the infrastructure underneath. Google is building the fire and then shutting down the fire department.

The open question: how many real vulnerabilities are slipping through while engineers dig out from AI-generated sludge — and who pays the price when one of them is exploited?