Loading prices...
All news
Lowered red and white boom barrier blocking a gold money bag on a dark ground

Google froze its bug bounty eleven months after FFmpeg told it to stop

10:00 · 05.10.2026
Source: TechCrunch
5

Google paused its Open Source Software Vulnerability Rewards Program on 1 October. The reason, in Google's own wording: «This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.» Researchers are pointed at Google's other bounty programmes, and an update is promised in Q1 2027, which puts the pause at three months at the earliest.

“is it really fair that trillion-dollar corporations run AI to find security issues in people's hobby code? Then expect volunteers to fix”

— Мейнтейнеры FFmpeg, Ноябрь 2025

The same complaint, sent the other way

FFmpeg wrote that in early November 2025, eleven months before the freeze. Google's Big Sleep agent had filed a vulnerability in FFmpeg's decoder for the Smush codec, which affects the first ten to twenty frames of Rebel Assault II, a LucasArts game from 1995. The maintainers called it CVE slop and gave Google a choice: fund the project or stop sending bugs.

Google did neither. Big Sleep reported its first twenty vulnerabilities in August 2025, into FFmpeg and ImageMagick among others. By June 2026 an AI agent had filed 21 zero-days into FFmpeg alone.

The two flows fail differently. Reports arriving at Google are invalid and waste a triage engineer's day. Reports Google sends out are valid and cost a volunteer a weekend. Both put the cost of AI-scale vulnerability hunting on whoever reads the report, and Google has stopped carrying it in the direction where Google does the reading. The accountability argument we covered last week turns on exactly this question of who absorbs what a model produces.

curl already ran this experiment

curl's documentation gives the whole policy in one sentence: «There is no bug bounty and the curl project never offers rewards for reported vulnerabilities.» Daniel Stenberg also closed vulnerability reporting for the whole of July 2026 and received roughly one report during the month.

Google has paused and set a date. curl removed the money and left the door open.

What the programme was worth

The OSS VRP launched on 30 August 2022, four years and one month before the freeze, paying between $100 and $31,337 per bug. Bazel, Angular, Go, Protocol Buffers and Fuchsia carry the top rewards. Google has reported over $110,000 paid to more than 100 bug hunters; that figure comes from its own 2023 reporting and it has not published a newer one.

We put Alphabet's Search revenue at $7,119 a second in September. The entire payout of the Google open source bug bounty is 15 seconds of it.

Q1 2027 begins about twelve weeks from now.

Informational material, not investment advice. Google has published no submission counts, so the scale of the inflow it describes is its own characterisation.

Published: 10:00 · 05.10.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came