Skip to content
All systems operational0 AI providers monitored, polled every 2 minutes
Live status
Back to Originals
Security · Open Source

Google Paused Its Open Source Bug Bounty Over a Flood of Automated Reports. Curl Dropped Its Bounty Money in January and Its Hit Rate Recovered.

Marcus Chen··6 min read

As of Thursday, October 1, Google is no longer accepting product vulnerability reports to its Open Source Software Vulnerability Reward Program, the OSS VRP. The reason, in Google's own words: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid."

Google posted the notice on X and on its Bug Hunters site. It promised an update in the first quarter of 2027. TechCrunch put the story in front of a wider audience on Sunday, and by Monday it was everywhere in the security press.

This is the company that paid researchers more than $17 million across its reward programs in 2025, an all-time high by its own count. It is also one of the companies selling the AI models that make writing a plausible vulnerability report nearly free. When Google cannot keep up with the triage, nobody can.

What Is Paused and What Is Not

The pause is narrower than the headlines suggest. Google says it covers OSS VRP product vulnerability submissions only. Supply chain reports under the same program are still accepted, and reports already in the queue are not affected.

Google is pointing researchers elsewhere: to find impact across its other VRPs and submit there, or to the Patch Rewards Program, which pays for security improvements rather than findings. Help Net Security notes that some Google Cloud repositories can still take product reports through the Cloud VRP.

The OSS VRP launched on August 30, 2022, covering projects such as Go, Angular, Bazel and Protocol Buffers. At launch, rewards ran from $100 to $31,337. SiliconANGLE reported it at the time as part of Google's broader $10 billion cybersecurity commitment.

Curl Already Ran This Experiment

Google is not the first to hit this wall. Daniel Stenberg, who leads curl, announced the end of the project's bug bounty in a blog post on January 26, and the program closed on January 31. It had run since April 2019, confirmed 87 vulnerabilities and paid out more than $100,000, according to Stenberg.

His numbers on why are the clearest public data we have seen on what automated reports do to a security team. In earlier years, more than 15 percent of curl's reports were confirmed vulnerabilities. In 2025 that rate fell below 5 percent. Stenberg wrote about the mental toll of "never-ending slop submissions" and said the point of dropping the money was to remove the incentive.

Then curl did something useful for everyone else. It briefly moved security reports to GitHub, found the tooling did not fit, and went back to HackerOne on March 1. The money did not come back. In Stenberg's words: "The reward money is still gone, there is no bug-bounty, no money for vulnerability reports."

On April 22, he reported the result. "The slop situation is not a problem anymore," he wrote. Reports were arriving at roughly double the 2025 rate, nearly all of them showed signs of AI assistance, and the confirmed rate was back in the 15 to 16 percent range.

 Google OSS VRPcurl
Program startedAugust 30, 2022April 2019
Payouts$100 to $31,337 per report at launchMore than $100,000 total for 87 confirmed bugs
Stated problemAutomated submissions, "the vast majority of which are not valid"Confirmed rate fell from above 15% to below 5% in 2025
ActionProduct reports paused October 1, 2026; supply chain reports still openBounty ended January 31, 2026; reports back on HackerOne from March 1 with no money
Outcome so farUpdate promised in Q1 2027Confirmed rate 15 to 16% by April; volume roughly double 2025

The Caveat in Curl's Numbers

It would be easy to read curl as proof that the bounty itself was the problem. We would not go that far. Two things changed at once between January and April: the money disappeared, and the models got better.

Stenberg's April post says almost every report now carries AI fingerprints. The difference is that far more of them are real. That fits what the labs have been claiming. In February, Anthropic said Claude Opus 4.6 had found more than 500 previously unknown high-severity flaws in open source code, each validated by its own team or an outside security researcher.

So curl's recovery may be part incentive design and part model quality. The two are hard to separate from one project's data, and curl is a single, unusually well-run codebase with a seven-year paper trail. Google is triaging across a whole portfolio of projects.

The industry did see this coming. That March grant, from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft and OpenAI, went to Alpha-Omega and the OpenSSF specifically to help maintainers keep up. Greg Kroah-Hartman of the Linux kernel said at the time: "Grant funding alone is not going to help solve the problem that AI tools are causing today on open source security teams." Six and a half months later, one of the funders has closed part of its own front door.

Our Take

We think Google made the right short-term call and has the wrong problem framed. Pausing is honest. A program that cannot triage its inbox is not paying for security; it is paying for noise and burning the maintainers it was meant to support.

But the fix is not fewer reports. Curl's volume roughly doubled and its team still came out ahead, because the reports got better. The lesson we take from curl is that cash per finding rewards volume, and volume is exactly what a model gives you for free. Reward reproduction, a working proof of concept and a patch, and the economics flip back toward the people doing real work.

The uncomfortable part for Google is that it sits on both sides of this. It sells frontier models, it helped fund the OpenSSF grant, and it paid out more than $17 million in bounties last year. It is better placed than anyone to require machine-checkable evidence with every submission. A Q1 2027 redesign that simply lowers payouts or adds friction would miss the opportunity.

Three signposts for the next 60 days: whether Google publishes any numbers on submission volume or valid rates to back up "significant rise"; whether another large program, on HackerOne, Bugcrowd or a vendor's own platform, pauses or drops cash rewards for open source findings; and whether Google moves money toward the Patch Rewards Program while the OSS VRP is closed to product reports.

For an earlier look at how AI is changing vulnerability discovery, see our analysis of the AI-cyber data layer.

Sources: Google VRP on X, TechCrunch, BleepingComputer, Help Net Security, ITPro, Google VRP 2025 Year in Review, SiliconANGLE (2022 launch), Daniel Stenberg: The end of the curl bug-bounty, curl security moves again, High-Quality Chaos, LWN.net, The Hacker News (Opus 4.6 findings), and OpenSSF ($12.5 million grant).