AI Spam Is Breaking the Way We Report Software Bugs

Google had to pause its open-source bug bounty program after AI-generated submissions flooded the queue. It's a warning sign for anyone who relies on community-driven security.

When the flood of fake reports drowns the real ones

Bug bounty programs are how the internet gets a lot of its security work done. Researchers find flaws in software and report them in exchange for recognition or a cash reward. The system works because humans make judgment calls: they check whether a vulnerability is real, whether it matters, and whether it hasn’t already been reported.

Google recently had to freeze its open-source bug bounty program — a scheme that paid researchers to find flaws in software Google publishes publicly — because AI-generated submissions had grown so numerous that staff couldn’t keep up. The reports looked plausible. They were just mostly useless.

Why this matters beyond Google

If you run a website or a server, you probably depend on open-source software without thinking about it much. Your web server, your database, your scripting language — most of it is maintained by communities that rely partly on bug bounties and responsible disclosure to catch problems before attackers do.

When those pipelines get clogged with AI-generated noise, two things happen. First, the people doing the reviewing burn out faster. Second, real vulnerability reports get buried in the queue and take longer to act on. That delay is the gap attackers look for.

The economics of AI slop

Generating a hundred plausible-sounding bug reports with an AI takes minutes and almost no money. Reviewing them takes human time. That asymmetry is the core problem. Some programs pay out for valid reports, which gives bad actors a financial reason to try their luck with AI-assisted submissions, hoping one slips through.

Google’s response — pausing the program entirely — is understandable but not a real fix. It just stops the bleeding while someone figures out a better filter. Other open-source projects, which have far fewer resources than Google, are facing the same flood with no equivalent staff to handle it.

What to watch for

If you maintain any open-source code yourself, even a small plugin or a public repository, you may start seeing more of this. Reports that sound technical and detailed but don’t quite connect to your actual codebase are a giveaway. Some projects are now asking submitters to prove basic familiarity before a report is even read.

The bigger picture is that AI is quietly shifting the cost of noise onto the people doing real work. Bug bounties are just one early example. As the tools get cheaper and easier to use, expect this pattern — AI-generated volume overwhelming human-curated systems — to show up in more places that the open web depends on.