Google halts OSS bug bounty over AI slop; Anthropic credits flood in
Google froze product vulnerability submissions to its Open Source Software Vulnerability Reward Program on 1 October, citing an influx of invalid AI-generated reports.

Google froze product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) on 1 October 2026, according to Tom's Hardware. The company said an influx of invalid AI-driven reports made triage unsustainable. New submissions are halted until the first quarter of 2027. Supply chain reports remain open, but code defect submissions are paused. Automated detection is outpacing manual verification in open source security infrastructure.
The suspension was announced via an official X post.
Google encouraged participants to explore other VRP programs during the pause. It committed to providing an update by Q1 2027 while it reformats the program. The decision affects only product vulnerabilities submitted after the freeze date. Prior reports will still be processed. Similar issues previously forced Linux to end support for older network drivers due to false bug reports.
The flood of false positives
AI models identify theoretical vulnerabilities with increasing speed. They often lack context to distinguish exploitable flaws from benign code patterns. The Register reported on 3 October that Anthropic's bug-hunting model, Mythos, is highly effective at math-related vulnerabilities. The sheer volume of AI findings is overwhelming open source maintainers. AI finds bugs faster than humans can fix them, but it also generates false alarms that erode trust in the process.
This dynamic is not unique to Google. A report by Caleb Gross at Offensive AI Con in San Diego in October 2025 demonstrated how LLMs can scale vulnerability research using listwise ranking algorithms. His open-source tools, Slice and Raink, prioritize targets to reduce manual effort. Slice reproduced the discovery of a use-after-free in the Linux kernel SMB server for approximately $3 per run. Raink ranks around 2,700 GitHub repositories to surface security-relevant items. These tools show the potential for efficiency, but they also illustrate the volume problem. When every repository is a potential target, the signal-to-noise ratio drops without rigorous triage.
Anthropic's contribution and verification challenges
While Google pauses, other actors are actively using AI to find and disclose vulnerabilities. A GitHub repository tracking CVEs credited to the Anthropic research team lists multiple high-severity issues disclosed on 2 October 2026. These include CVE-2026-103604 and CVE-2026-103603 in Legion of the Bouncy Castle's bc-csharp library, both rated 8.7 on the CVSS scale. The repository also lists CVE-2026-66858 in Apache Thrift, credited to Claude (Anthropic Research) and Ada Logics. The volume of such disclosures is increasing, but verification remains a bottleneck. Maintainers often lack the resources to validate every AI-generated claim, leading to delays in patching genuine flaws.
The Guardian reported on 3 October that David Robinson, a former OpenAI safety leader, quit the company warning that its culture was "broken." He argued that AI firms are not "being nearly careful enough" in their development pace. His focus was on safety culture, but the underlying issue applies to security. Rapid deployment without adequate oversight creates systemic risks. In open source, AI-driven findings are flooding in faster than the ecosystem can absorb them. The result is a fragmented environment where some vulnerabilities are addressed quickly, while others languish in triage queues.
Infrastructure and architectural vulnerabilities
Beyond AI-generated noise, open source infrastructure faces traditional architectural risks. A GitHub issue on 4 October 2026 revealed that Xray-core, a popular proxy software, concealed a certificate verification bypass vulnerability for half a year. The issue described how the pinnedPeerCertSha256 option, introduced in January 2026, contained a flaw that allowed man-in-the-middle attacks. The maintainers had replaced a previous option with this new one, effectively removing a layer of security without adequate warning. Manual code changes in critical infrastructure can introduce subtle vulnerabilities that persist until discovered by independent researchers.
Similarly, the OpenBSD developers rejected a port of the uutils coreutils reimplementation on 30 September 2026, citing licensing and compatibility concerns. Theo de Raadt, the project founder, argued that introducing "subtly different" binaries would break existing pipelines and violate the system's cohesion. This decision reflects a broader tension in open source: the desire to adopt new tools versus the need for stability and consistency. In security-critical environments, such as those running on OpenBSD, even minor behavioral differences can have significant implications.
Path forward
The current situation requires a balance between using AI for efficiency and maintaining human oversight for verification. Google's pause is a pragmatic response to an unsustainable workflow, but it also signals a need for better standards in AI-generated vulnerability reporting. Tools like Slice and Raink offer promising methods for prioritization, but they must be paired with rigorous triage processes. The community must also address the root cause: the gap between AI detection capabilities and human remediation capacity. Without this balance, open source security will continue to struggle with both the flood of false positives and the slow pace of fixing genuine flaws.
Sources
9- 01Google freezes open-source bug bounty program amid flood of invalid AI slopEN
- 02Tracking vulnerabilities that credit the Anthropic research teamEN
- 03O(N) the Money: Scaling Vulnerability Research with LLMs (2025)EN
- 04OpenAI safety leader quits, warning AI company's culture is 'broken'EN
- 05Xray-core concealed a certificate verification bypass vulnerabilityEN
- 06OpenBSD Developers Reject uutils Coreutils Port Over Licensing and Compatibility ConcernsEN
- 07PhotoSuite Is an Open Source Photoshop-Like Editor with Native PSD SupportEN
- 08UberDDR4: The Open-Source DDR4 ControllerEN
- 09Kyber open source remote streaming solution architectureEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.