GitHub Halves Public Bug Bounty Payouts and Unveils VIP Tier

GitHub bug bounty payouts restructuring diagram showing public vs VIP reward tiers

Redefining Value in an Automated Era

As automated vulnerability discovery becomes increasingly frictionless, software developers place an unprecedented premium on verified, empirical results. Effective July 27 of this year, GitHub will slash rewards for participants in its public bug bounty program by at least fifty percent. Concurrently, the organization will migrate its highest financial tier to an exclusive, invite-only VIP program.

Drastic Reductions Across Public Tiers

Under the revised guidelines, GitHub will issue a fixed sum of $10,000 for critical vulnerabilities reported within the public program, departing from the previous range of $20,000 to $30,000 or higher. Compensation for high-risk vulnerabilities will decrease to $5,000, medium-risk issues to $2,000, and low-risk flaws to $250. Submissions transmitted prior to July 27 will retain legacy compensation terms, including pending reports awaiting formal verification.

Premium Compensation via the Exclusive VIP Tier

Conversely, the invite-only VIP program offers substantially higher remuneration. A critical finding will command $30,000 or more, high-risk vulnerabilities $20,000, medium-risk flaws $7,500, and low-risk issues $1,000. Security researchers who have successfully disclosed at least one critical, two high, four medium, or seven low-severity vulnerabilities will qualify to seek an invitation. However, GitHub has yet to specify the temporal window required to achieve these benchmarks, nor does fulfilling these thresholds guarantee automated admission.

Stemming the Influx of Low-Quality Submissions

GitHub aims to diminish the influx of superficial, automatically generated submissions, expedite the triage of high-quality disclosures, and foster closer collaboration with vetted researchers. Additional restrictions will target contributors with low HackerOne Signal scores, limiting them to a maximum of four initial submissions, though GitHub has not yet articulated the precise rating threshold.

The Impact of AI-Generated Reports

These structural changes emerge alongside the rapid proliferation of artificial intelligence tools capable of swiftly analyzing source code and generating vast quantities of hypothetical findings. While such systems empower researchers and internal security teams to audit repositories with greater frequency, they simultaneously generate an overwhelming volume of spurious or unverified reports. Previously, the curl open-source project suspended cash bounties entirely following a deluge of low-grade, AI-assisted reports.

Strict Standards for AI Usage

While GitHub does not prohibit the employment of AI in security research, it mandates that researchers independently reproduce their findings, substantiate the operational impact, and strictly adhere to program policies. A plausible narrative alone will no longer suffice to secure a payout: reports must provide a functional proof of concept, account for system architecture, and demonstrate tangible risk.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply