Security researchers hoping to earn a Google Bug Bounty payout for open-source flaws have hit a wall. Google has paused new product-vulnerability submissions to its open-source rewards scheme, saying a surge of automated reports — most of them invalid — has overwhelmed the engineers and maintainers who review them, according to BleepingComputer. The freeze took effect at the start of October 2026, and the company says an update will follow in the first quarter of 2027.

The Google Bug Bounty halt is narrower than the headlines suggest. Reports filed before October 1, 2026 will still be processed, supply-chain submissions remain open, and researchers can still earn money through the company's program that pays for accepted open-source fixes, with top rewards reaching fifteen thousand dollars for high-impact work. Product bugs tied to Google Cloud repositories can still go through the cloud division's own rewards track, as reported by TechCrunch.

The frozen scheme is Google's Open Source Software Vulnerability Rewards Program, which covers flaws in projects including Go, Angular, and Protocol Buffers, plus repository settings and critical third-party dependencies. It launched in August 2022 to protect the software supply chain by paying outside researchers to report weaknesses responsibly before attackers could exploit them.

A timeline from March to October: how the pause happened

In March 2026, Google tried to save the Google Bug Bounty program with a gentler fix. It rewrote the rules to demand stronger proof for some tiers, such as a reproduction through its fuzzing infrastructure or a merged patch, after machine-made reports began carrying hallucinated exploit paths or flagging flaws with little security impact. In April 2026, the company overhauled its Chrome and Android programs along similar lines and dropped bonuses introduced the previous year, according to security industry coverage.

The softer approach did not hold. Engineers and open-source maintainers were buried under reports that read convincingly but collapsed on inspection, and the hours spent disproving submissions were hours not spent fixing genuine flaws, as Tom's Hardware reported. Google said the pause came down to a significant rise in automated submissions, the vast majority of them invalid — and intake stopped in October 2026 rather than letting the queue keep growing.

Google is the biggest company to pause a Google Bug Bounty track, but it is not the first to crack. In January 2026, the maintainer of the curl utility ended that project's HackerOne bounty after being overwhelmed by automated reports. In September 2026, Intel stripped financial rewards from reports on its Intigriti program covering software, firmware, hardware, and services, without publicly explaining the move. Bugcrowd has also rewritten its policies around automated findings, and Apple is reportedly struggling with the same flood.

Payouts show what the Google Bug Bounty was worth

The stakes were high. Since launching its first rewards program in 2010, Google has paid out over eighty-one million dollars to thousands of researchers. The year 2025 set a record: seventeen million dollars to more than seven hundred researchers, about forty percent more than the twelve million dollars paid the year before. Individual open-source rewards at launch ranged from a hundred dollars to more than thirty-one thousand dollars, aimed at the flaws with the biggest supply-chain impact — which made the Google Bug Bounty one of the richest incentives in open source.

The industry is now paying to fix the system itself. In March 2026, the Linux Foundation announced twelve and a half million dollars in grants from a coalition of major technology companies — Google among them — to build triage tooling and give maintainers backup against the flood of automated findings, according to The Register. A Linux kernel maintainer cautioned that funding alone would not solve the problem, but said the foundation's resources could help projects process the growing pile of automated reports.

What the Google Bug Bounty freeze means for new researchers

For students and early-career hackers who saw the Google Bug Bounty as a way into security work, the freeze closes the most visible door. The realistic paths now run through what Google left open: supply-chain reports, the cloud rewards track, and the program paying for accepted patches. The deeper lesson is about what still wins: volume no longer works, and the reports that get paid are the ones with reproducible proof and real-world impact. Learning to build a working demonstration matters more than ever.

Gen Z already lives inside the code these programs protect. For more coverage of how technology and policy collide, see Tech & Games, and read our earlier reporting on iOS 26.7.1 security update fixes zero-day used in targeted attacks for a look at how fast real flaws move once they are found.

The counterpoint: not every AI report is junk

It would be wrong to conclude that AI has nothing to offer security. Microsoft warned in May that AI tools help surface far more vulnerabilities across the industry, and Google's own DeepMind-built tools have identified and fixed complex flaws, including in its browser. The technology is genuinely accelerating discovery — the breakdown is in verification. Every report still needs a human to reproduce it, argue with it, and close it, and review capacity has not scaled the way report generation has.

That mismatch is the story behind the Google Bug Bounty pause: discovery got cheap while proof stayed expensive. If the program returns in 2027 with tougher evidence rules, the hunters who survive will be the ones who treat AI as a starting point and do the hard verification work themselves. The flood only stops when the signal is worth more than the noise.