GitHub Slashes Public Bug Bounty Payouts by 50% as Security Focus Shifts to Exclusive VIP Tier

In a major structural overhaul of its security reward ecosystem, GitHub announced that it will reduce public bug bounty payouts by approximately 50% across all severity levels, effective July 27, 2026.

The move shifts GitHub away from wide payout ranges toward flat, static rewards for public submissions, while rolling out a formal, invite-only VIP program designed to lavish top-tier researchers with higher rewards and direct access to GitHub’s internal security engineering team.

Why the Change? Signal vs. Noise in the Era of AI

According to Catherine Cassell, GitHub Security Lead, the program changes follow months of internal evaluation and a surging queue of incoming submissions.

The explosion of automated scanner output and low-effort, AI-generated reports across crowdsourced platforms has created a severe triage burden across the industry. By restructuring the public tier, GitHub aims to curb low-quality submissions while incentivizing researchers to build long-term relationships through high-impact work.

“These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in… You don’t earn more by submitting more. You earn more by submitting better.”GitHub Security Announcement

Breakdown: Old Public Rates vs. New Public Rates

Under the previous model, GitHub awarded bounty payouts based on variable ranges. Starting July 27, 2026, the public program moves to fixed, static payouts per severity level:

SeverityOld Public RangeNew Public Fixed Payout% Reduction (vs Old Floor/Average)
Low$617 – $2,000$250~59% reduction
Medium$4,000 – $10,000$2,00050% reduction
High$10,000 – $20,000$5,00050% reduction
Critical$20,000 – $30,000+$10,00050%+ reduction

 

Note: All reports submitted before July 27, 2026—including those currently pending in triage—will still be honored under the previous, higher reward structure.

The New Invite-Only VIP Program

To retain and reward veteran security researchers, GitHub is formalizing a permanent VIP Tier. Researchers in the VIP program will benefit from faster triage response times, dedicated security engineering channels, and substantially higher reward ceilings.

VIP Payout Schedule

  • Low: $1,000

  • Medium: $7,500

  • High: $20,000

  • Critical: $30,000+

How to Qualify for VIP Status

To earn an invitation into GitHub’s VIP tier, researchers must establish a proven track record by submitting at least one of the following on the public program:

  • 1 Critical finding

  • 2 High severity findings

  • 4 Medium severity findings

  • 7 Low severity findings

Additional Friction: HackerOne Signal Thresholds

In addition to rate cuts, GitHub is introducing a strict HackerOne Signal Requirement for public submissions. Researchers who do not meet the minimum signal score will face tight caps on the number of reports they can submit at any given time until they build a track record of valid findings.

This follows earlier policy updates requiring working proof-of-concept (PoC) exploits and demonstrated security impact before a submission is accepted for review.

What This Means for Bug Bounty Hunters

GitHub’s decision reflects a broader trend across tech giants (including recent pivots seen with projects like curl and major enterprise VDPs) struggling under the weight of AI-assisted noise.

  • For entry-level researchers: The public pool will yield significantly lower monetary returns, making GitHub less attractive as a starting ground for casual bounty hunting.

  • For seasoned professionals: The path forward relies on hitting the VIP criteria quickly to unlock $30,000+ critical bounties and direct engineering access.

References & Further Reading

  1. GitHub Security Blog: Next chapter: Restructuring GitHub’s bug bounty program (Published July 22, 2026)

  2. The Hacker News: GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier (Published July 22, 2026)

  3. HackerOne Policy Guidelines: GitHub Bug Bounty Program Scope & Terms

 

 

Facebook
Twitter
LinkedIn
WhatsApp
Reddit
Telegram
GitHub Slashes Public Bug Bounty Payouts by 50% as Security Focus Shifts to Exclusive VIP Tier
Scroll to top