Cybersecurity

GitHub Restructures Bug Bounty Program Slashing Public Payouts Amid AI-Driven Report Surge

GitHub has announced a significant restructuring of its bug bounty program that will see public payout rates for security vulnerabilities slashed by more than 50% across most severity levels. Starting July 27, 2026, the Microsoft-owned platform will move away from its long-standing flexible reward ranges in favor of a fixed-price model for the general public, while simultaneously pivoting its focus toward a permanent, invite-only "VIP" tier for elite researchers. Under the new schedule, a critical vulnerability that previously commanded between $20,000 and $30,000 or more will now be capped at a flat $10,000 for public contributors. Conversely, researchers who qualify for the VIP tier will remain eligible for rewards of $30,000 or higher for similar findings.

The company has clarified that any reports filed before the July 27 deadline, including those currently sitting in GitHub’s extensive triage queue, will be processed under the existing, more generous terms. This move represents one of the most substantial shifts in the economics of crowdsourced security since GitHub launched its bounty program, reflecting a broader industry trend where organizations are struggling to balance the benefits of public disclosure with an overwhelming volume of low-quality, automated submissions.

A Drastic Shift in Bounty Economics

The transition from flexible reward ranges to a fixed-payment structure marks a definitive end to the era of high-ceiling public payouts at GitHub. According to calculations based on the company’s previous reward tiers, the new rates represent a 50% reduction for medium, high, and critical findings. Low-severity reports have been hit even harder, with the new $500 flat fee representing an approximately 59% decrease when measured against the bottom of the previous $1,200 to $2,000 range.

The new public reward structure is as follows:

  • Low Severity: $500 (Fixed)
  • Medium Severity: $2,000 (Fixed)
  • High Severity: $5,000 (Fixed)
  • Critical Severity: $10,000 (Fixed)

In contrast, the VIP program offers a significantly more lucrative incentive for established researchers:

  • Low Severity: $1,000
  • Medium Severity: $7,500
  • High Severity: $20,000
  • Critical Severity: $30,000 or more

GitHub maintains that these fixed payments are designed to remove uncertainty and reduce the administrative overhead associated with triaging thousands of reports. By standardizing the "market price" for a bug, the company hopes to discourage "bounty hunting" for marginal gains and instead incentivize researchers to focus on high-impact, complex vulnerabilities that require deep manual analysis. Despite the move to fixed rates, GitHub has noted that it reserves the right to award discretionary bonuses for "exceptional work" that goes above and beyond a standard vulnerability report.

The AI Factor: Quantity vs. Quality

The primary driver behind this restructuring appears to be the rapid proliferation of Artificial Intelligence in the cybersecurity space. GitHub’s announcement coincides with a period where AI models have made it significantly cheaper for researchers to generate "candidate findings"—potential bugs that may or may not be exploitable. However, while AI can identify thousands of potential code flaws, the human cost of verifying, triaging, and remediating those flaws remains high.

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

"You don’t earn more by submitting more," GitHub stated in its official communication regarding the change. "You earn more by submitting better."

This sentiment is echoed across the industry. Just one day prior to GitHub’s announcement, Google unveiled Gemini 3.5 Flash Cyber, a specialized, lightweight AI model fine-tuned specifically for the identification, validation, and patching of software vulnerabilities. During internal testing, Google reported that the model was able to identify 55 unique confirmed vulnerabilities in the V8 engine, outperforming larger frontier models like Claude 4.6. More impressively, Google’s Cloud Vulnerability Research team used the model to discover a memory-corruption flaw in a production service and generate a 100%-reliable remote code execution (RCE) exploit that bypassed advanced security mitigations like ASLR (Address Space Layout Randomization) and W^X (Write or Execute) within just two hours.

The existence of such tools changes the fundamental value proposition of a public bug bounty. When an internal security team can use a tool like Gemini 3.5 Flash Cyber or OpenAI’s Codex Security to scan every commit in real-time, the "low-hanging fruit" that public researchers used to find manually is often patched before a report can even be filed. Consequently, GitHub is shifting its financial weight toward the VIP tier—researchers who can find the complex, multi-stage attack chains that AI is not yet capable of fully conceptualizing.

Chronology of the Policy Evolution

The July 2026 restructuring is the culmination of a series of policy adjustments GitHub has implemented over the past year to tighten its security perimeter and manage researcher expectations.

  • January 2026: Daniel Stenberg, the maintainer of the ubiquitous curl project, announced the end of the project’s cash bug bounty. Stenberg cited an overwhelming influx of AI-generated "junk" reports, noting that the rate of confirmed vulnerabilities had plummeted below 5%.
  • April 2026: After moving back to the HackerOne platform and removing cash rewards, curl saw a surprising shift. While report volume doubled compared to 2025, the quality improved, with 15-16% of reports being confirmed as legitimate vulnerabilities, many of which appeared to be AI-assisted but high-quality.
  • May 2026: GitHub updated its own vulnerability disclosure policy, raising the bar for submissions. The new rules required all reports to include a working proof of concept (PoC), a clear demonstration of material impact, and evidence of validation before submission.
  • July 2026: GitHub announces the official slashing of public rewards and the formalization of the VIP tier, effective July 27.

This timeline illustrates a clear trajectory: as automated discovery tools become ubiquitous, software vendors are moving to protect their engineering teams from "noise" by increasing the technical requirements for submission while simultaneously decreasing the financial reward for easily discovered flaws.

The VIP Tier: An Exclusive Club

For researchers, the path to maintaining a high income through GitHub’s program now leads exclusively through the VIP tier. To qualify for an invitation, a researcher must demonstrate a consistent track record of high-quality work. The current thresholds for qualification include reporting at least one critical, two high, four medium, or seven low-severity vulnerabilities.

However, meeting these numerical targets does not guarantee entry. GitHub has stated that it will review candidates on a quarterly basis and that invitations are discretionary. Furthermore, the company has not publicly disclosed the specific "HackerOne Signal" threshold it will enforce for its public program. The Signal score is a metric used by the HackerOne platform to measure the accuracy and relevance of a researcher’s reports. Researchers who fall below the required threshold will be limited to just four initial submissions, a move designed to prevent "spamming" of the triage queue.

This "invite-only" approach has drawn mixed reactions from the security community. Proponents argue that it allows GitHub’s security engineering team to build closer, more collaborative relationships with trusted experts, leading to faster response times and better security outcomes. Critics, however, worry that it creates a "closed shop" environment that makes it nearly impossible for new talent to break into the industry. For a researcher just starting their career, a four-report limit and a $10,000 cap on critical findings may make other platforms or private programs more attractive than GitHub.

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Broader Implications for the Cybersecurity Ecosystem

GitHub’s decision is likely to serve as a bellwether for other major technology companies. As AI continues to commoditize the "discovery" phase of vulnerability research, the "verification" phase becomes the primary source of value. We are entering an era where the ability to find a bug is no longer a rare skill; the rare skill is the ability to prove that a bug matters within the specific context of a complex, global production environment.

The restructuring also highlights the growing divide between internal automated security and external crowdsourced security. If GitHub and Google can use AI to find and patch 80% of vulnerabilities during the development cycle, the role of the external researcher shifts from "broad-spectrum scanner" to "specialized surgical auditor."

Furthermore, the emphasis on "material impact" and "working PoCs" suggests that vendors are no longer willing to pay for theoretical risks. In the past, a researcher might be rewarded for finding a memory leak that could theoretically lead to an exploit. In the new regime, the researcher must often provide the exploit itself to receive the top-tier payout. This effectively shifts the burden of proof—and the associated labor costs—from the vendor to the researcher.

Conclusion: The Premium on Human Expertise

GitHub’s move to slash public payouts while rewarding VIPs is a calculated bet on the future of security. By pricing public critical findings at $10,000 and VIP findings at $30,000, GitHub is explicitly valuing the researcher’s identity, history, and proven reliability over the vulnerability itself.

As of late July 2026, GitHub’s rewards page and FAQ still reflect some of the older criteria, including a requirement for researchers to have earned at least $20,000 in the preceding two years to be considered for VIP status. These pages are expected to be updated as the July 27 deadline approaches.

For the global community of security researchers, the message from GitHub is clear: the tools used to find bugs—whether they are manual scripts or advanced AI models like Gemini—are secondary to the quality of the final output. In a world where "plausible-looking" bugs are becoming abundant and cheap to find, the premium remains on verified, product-specific impact that only a highly skilled human researcher can consistently demonstrate. The restructuring of the GitHub Bug Bounty Program is not just a change in pricing; it is a fundamental revaluation of what it means to be a security researcher in the age of artificial intelligence.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Jar Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.