Jul 23, 2026
Policy

GitHub bug bounty payouts fall for public reports as VIP tier opens

GitHub will cut public bug bounty rewards on July 27 while reserving larger payouts for invited researchers with accepted findings.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

GitHub bug bounty payouts fall for public reports as VIP tier opens
Photo: The Register

GitHub bug bounty payouts are changing on July 27, with public rewards falling sharply and a new invite-only tier taking over the top end of the program. The Microsoft-owned company said the redesign is meant to reduce low-quality and AI-generated vulnerability reports while paying more to researchers with a record of accepted findings.

The change creates two tracks. Public submissions will remain open, but the payout bands are being reduced across severity levels. A separate VIP program will offer higher awards to researchers GitHub invites based on prior valid reports.

GitHub product security engineer Cathering Cassell said the changes are intended to cut noise and make the program more useful for experienced participants. “These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in,” Cassell said.

Why did GitHub cut bug bounty payouts?

GitHub said bug bounty programs are receiving more low-effort and AI-assisted submissions, creating extra review work for security teams. The company’s answer is to limit the economics and volume of public reporting while putting larger awards behind a qualification gate.

For technology companies running bounty programs, the move is a public acknowledgment of a growing operational problem: generative AI can help more people produce plausible-looking reports, but triage teams still have to separate real vulnerabilities from weak or invalid claims. GitHub is betting that a smaller number of higher-signal reports is worth more than a larger queue of submissions.

How the new GitHub rewards compare

  • Low-severity public reports will pay $250, down from the previous $500 to $1,000 range.
  • Medium-severity public reports will pay up to $2,000, down from a prior maximum of $5,000.
  • High-severity public reports will pay up to $5,000, down from a prior maximum of $20,000.
  • Critical public reports will pay up to $10,000, down from a prior maximum of $30,000.

The VIP tier reverses that pattern for invited researchers. GitHub said low-severity findings in the new tier will be worth $1,000, medium findings $7,500, high-severity findings $20,000, and critical vulnerabilities at least $30,000.

Access to the VIP tier will be based on a history of accepted findings. GitHub said the qualification threshold can range from one accepted critical vulnerability to seven accepted low-severity reports, depending on the researcher’s record.

New researchers will face submission limits

GitHub is also turning on HackerOne’s “signal requirement,” which limits the number of reports newer participants can send before they establish a track record of legitimate submissions. GitHub said legitimate newcomers will still have as many as four chances to prove themselves.

Reports already in GitHub’s backlog will be reviewed under the prior payout structure, according to the company. The update follows earlier program changes this year in which GitHub tightened report-quality rules and warned researchers against overwhelming the platform with AI-assisted reports.

The company did not disclose how many reports it has received, what share it believes are AI-generated, or how many researchers will be invited into the VIP program. Those omissions matter: the new structure changes the incentives for public researchers, but GitHub has not published the volume data that would show how much of the program’s review burden comes from AI-assisted submissions.

This story draws on original reporting from The Register.

More from Policy

All Policy →