
Google froze its bug bounty eleven months after FFmpeg told it to stop
Google paused its Open Source Software Vulnerability Rewards Program on 1 October. The reason, in Google's own wording: «This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.» Researchers are pointed at Google's other bounty programmes, and an update is promised in Q1 2027, which puts the pause at three months at the earliest.
“is it really fair that trillion-dollar corporations run AI to find security issues in people's hobby code? Then expect volunteers to fix”
— Мейнтейнеры FFmpeg, Ноябрь 2025
The same complaint, sent the other way
FFmpeg wrote that in early November 2025, eleven months before the freeze. Google's Big Sleep agent had filed a vulnerability in FFmpeg's decoder for the Smush codec, which affects the first ten to twenty frames of Rebel Assault II, a LucasArts game from 1995. The maintainers called it CVE slop and gave Google a choice: fund the project or stop sending bugs.
Google did neither. Big Sleep reported its first twenty vulnerabilities in August 2025, into FFmpeg and ImageMagick among others. By June 2026 an AI agent had filed 21 zero-days into FFmpeg alone.
The two flows fail differently. Reports arriving at Google are invalid and waste a triage engineer's day. Reports Google sends out are valid and cost a volunteer a weekend. Both put the cost of AI-scale vulnerability hunting on whoever reads the report, and Google has stopped carrying it in the direction where Google does the reading. The accountability argument we covered last week turns on exactly this question of who absorbs what a model produces.
curl already ran this experiment
curl's documentation gives the whole policy in one sentence: «There is no bug bounty and the curl project never offers rewards for reported vulnerabilities.» Daniel Stenberg also closed vulnerability reporting for the whole of July 2026 and received roughly one report during the month.
Google has paused and set a date. curl removed the money and left the door open.
What the programme was worth
The OSS VRP launched on 30 August 2022, four years and one month before the freeze, paying between $100 and $31,337 per bug. Bazel, Angular, Go, Protocol Buffers and Fuchsia carry the top rewards. Google has reported over $110,000 paid to more than 100 bug hunters; that figure comes from its own 2023 reporting and it has not published a newer one.
We put Alphabet's Search revenue at $7,119 a second in September. The entire payout of the Google open source bug bounty is 15 seconds of it.
Q1 2027 begins about twelve weeks from now.
Informational material, not investment advice. Google has published no submission counts, so the scale of the inflow it describes is its own characterisation.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news

Fourteen parallel agents asked one question for seven days, then stopped

Morgan Stanley's $1bn bitcoin milestone needs a price, not another purchase

Stripe says it is stablecoin agnostic. Its own one launched the day before
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
344AI


