Xint
Products
Xint Platform Xint Pulse
Resources
Blog Public Bug Tracker
About
Login
Web App Code App
Talk to an Expert
EN KR
Products
Xint Platform Xint Pulse
Resources
Blog Public Bug Tracker
About Theori
Login
Web App Code App
Talk to an Expert
Language
EN KR
NewsOpen Source Projects

Google stopped paying for tails

Reports are commoditized. What actually matters for bug discovery is validation and remediation.
Jeffrey Martin's avatar
Jeffrey Martin
Oct 06, 2026
Google stopped paying for tails
Contents
Rat tailsProof won't save itWhere that leaves the rest of us

Last week Google stopped taking product vulnerability reports through its open source bug bounty, the OSS VRP. Its reason was "a significant rise in automated submissions, the vast majority of which are not valid." It plans to give an update in Q1 2027.

Most of the coverage stops at AI slop. What caught my eye was the list of what Google kept open. Supply chain reports still count. So does the Cloud VRP. And the Patch Rewards Program, which pays people to fix things, is still paying. Google didn't stop paying for security work. It stopped paying for reports.

It isn't the first, either. curl killed its bounty in January after seven years. HackerOne's Internet Bug Bounty paused in March. GitHub started demanding working proofs of concept in May, then cut its public payouts in July. Something is off in how this market prices things, and I keep coming back to a story about rats.

Rat tails

The historian Michael Vann is the one who dug this story up. In 1902 Hanoi was worried about plague, and the French colonial government put a bounty on rats. Counting dead rats turned out to be a miserable job, so officials started accepting just the tail.

People cut off the tails and let the rats go. A rat with no tail can still breed, and its babies have tails. Somebody started farming them. The bounty got scrapped, and plague showed up anyway.

The rat catchers weren't villains. They were poor people doing the obvious thing with a badly designed incentive. I'd say the same about most of the people pointing LLMs at bug bounty forms today.

A vulnerability report has always been a rat tail. It stands in for what you actually care about, a bug that's real and exploitable, and it was never a great stand-in. Even before AI, roughly 85% of the reports curl got didn't pan out. What kept it workable was cost. A convincing report took a researcher hours, so the junk stayed small enough to handle.

LLMs made the report basically free. Proving it and fixing it still cost what they always did.

Proof won't save it

The obvious response is to stop taking tails and make people bring the whole rat. Google did exactly that in March, when it started requiring stronger proof for some reward tiers, with a patch already merged into the project as one accepted form. GitHub did it in May. Both pulled back anyway.

curl shows why. Once the money went away, most of the junk left with it, and the confirmed rate climbed back to about where it was before AI. Then the real reports started arriving at twice last year's pace, nearly all of them made with AI help. Daniel Stenberg's take in April: "This avalanche is going to make maintainer overload even worse." In June he announced curl would stop taking security reports for all of July. His reason wasn't junk: "We have been under a huge pressure for the last four months or so. Now we need some rest."

HackerOne's platform data says the same thing at scale. In the year to March, submissions went up about 76%. Teams fixed individual bugs about 80% faster and still closed 46% fewer per month, because there were just too many. The backlog of confirmed, unfixed vulnerabilities grew 21x. When HackerOne paused the Internet Bug Bounty, its explanation was that the balance between findings and remediation capacity "has substantively shifted."

So proof gets rid of the fake tails. It does nothing about a pile of real rats growing faster than anyone can deal with. Finding bugs is the cheap part now. Proving they matter and getting them fixed is where the cost went, and bounties were paying for the wrong end of that.

That's why Patch Rewards staying open is, to me, the most telling detail in Google's announcement.

Where that leaves the rest of us

If you run a disclosure program, pay for fixes, not reports. And make whoever finds the bug do the work of proving it, instead of handing that bill to your maintainers.

If you buy security tools, ask whether a finding comes with a reproduction, a reachable path and some reason to believe it matters in your environment. If it doesn't, you bought a tail. Doesn't matter whether it came from a SAST scanner or the newest agent.

That question applies to us too, and I'd rather say so than have someone else point it out. Xint builds AI that finds vulnerabilities, and this year we've reported real ones to Google, OpenAI and the Spring maintainers. We're part of the pile. The bar we hold ourselves to is not sending a claim we haven't proven.

Pausing payouts doesn't pause the bugs, either. Last week attackers started exploiting a Rejetto HFS flaw that Horizon3 found with Anthropic's Mythos model. The patch had been out since July.

I'd have made Google's call. But if your security program still measures itself by how many findings it turns up, that's the number I'd stop watching. Count dead rats, not tails.

Share article
Contents
Rat tailsProof won't save itWhere that leaves the rest of us
Xint

AI-powered vulnerability discovery that proves exploitability in your live application.

XLinkedInBlueskyFediverse
Products
Xint PlatformXint Pulse
Company
AboutContact
Resources
BlogPublic Bug Tracker
Legal
Privacy PolicyTerms of UseTrust Center
© 2026 Theori. All Rights Reserved.