In a major structural overhaul of its security reward ecosystem, GitHub announced that it will reduce public bug bounty payouts by approximately 50% across all severity levels, effective July 27, 2026.
The move shifts GitHub away from wide payout ranges toward flat, static rewards for public submissions, while rolling out a formal, invite-only VIP program designed to lavish top-tier researchers with higher rewards and direct access to GitHub’s internal security engineering team.
Why the Change? Signal vs. Noise in the Era of AI
According to Catherine Cassell, GitHub Security Lead, the program changes follow months of internal evaluation and a surging queue of incoming submissions.
The explosion of automated scanner output and low-effort, AI-generated reports across crowdsourced platforms has created a severe triage burden across the industry. By restructuring the public tier, GitHub aims to curb low-quality submissions while incentivizing researchers to build long-term relationships through high-impact work.
“These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in… You don’t earn more by submitting more. You earn more by submitting better.” — GitHub Security Announcement
Breakdown: Old Public Rates vs. New Public Rates
Under the previous model, GitHub awarded bounty payouts based on variable ranges. Starting July 27, 2026, the public program moves to fixed, static payouts per severity level:
| Severity | Old Public Range | New Public Fixed Payout | % Reduction (vs Old Floor/Average) |
| Low | $617 – $2,000 | $250 | ~59% reduction |
| Medium | $4,000 – $10,000 | $2,000 | 50% reduction |
| High | $10,000 – $20,000 | $5,000 | 50% reduction |
| Critical | $20,000 – $30,000+ | $10,000 | 50%+ reduction |
Note: All reports submitted before July 27, 2026—including those currently pending in triage—will still be honored under the previous, higher reward structure.
The New Invite-Only VIP Program
To retain and reward veteran security researchers, GitHub is formalizing a permanent VIP Tier. Researchers in the VIP program will benefit from faster triage response times, dedicated security engineering channels, and substantially higher reward ceilings.
VIP Payout Schedule
Low: $1,000
Medium: $7,500
High: $20,000
Critical: $30,000+
How to Qualify for VIP Status
To earn an invitation into GitHub’s VIP tier, researchers must establish a proven track record by submitting at least one of the following on the public program:
1 Critical finding
2 High severity findings
4 Medium severity findings
7 Low severity findings
Additional Friction: HackerOne Signal Thresholds
In addition to rate cuts, GitHub is introducing a strict HackerOne Signal Requirement for public submissions. Researchers who do not meet the minimum signal score will face tight caps on the number of reports they can submit at any given time until they build a track record of valid findings.
This follows earlier policy updates requiring working proof-of-concept (PoC) exploits and demonstrated security impact before a submission is accepted for review.
What This Means for Bug Bounty Hunters
GitHub’s decision reflects a broader trend across tech giants (including recent pivots seen with projects like curl and major enterprise VDPs) struggling under the weight of AI-assisted noise.
For entry-level researchers: The public pool will yield significantly lower monetary returns, making GitHub less attractive as a starting ground for casual bounty hunting.
For seasoned professionals: The path forward relies on hitting the VIP criteria quickly to unlock $30,000+ critical bounties and direct engineering access.
References & Further Reading
GitHub Security Blog: Next chapter: Restructuring GitHub’s bug bounty program (Published July 22, 2026)
The Hacker News: GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier (Published July 22, 2026)
HackerOne Policy Guidelines: GitHub Bug Bounty Program Scope & Terms