GitHub Halves Public Bug Bounty Payouts and Unveils VIP Tier
Redefining Value in an Automated Era
As automated vulnerability discovery becomes increasingly frictionless, software developers place an unprecedented premium on verified, empirical results. Effective July 27 of this year, GitHub will slash rewards for participants in its public bug bounty program by at least fifty percent. Concurrently, the organization will migrate its highest financial tier to an exclusive, invite-only VIP program.
Drastic Reductions Across Public Tiers
Under the revised guidelines, GitHub will issue a fixed sum of $10,000 for critical vulnerabilities reported within the public program, departing from the previous range of $20,000 to $30,000 or higher. Compensation for high-risk vulnerabilities will decrease to $5,000, medium-risk issues to $2,000, and low-risk flaws to $250. Submissions transmitted prior to July 27 will retain legacy compensation terms, including pending reports awaiting formal verification.
Premium Compensation via the Exclusive VIP Tier
Conversely, the invite-only VIP program offers substantially higher remuneration. A critical finding will command $30,000 or more, high-risk vulnerabilities $20,000, medium-risk flaws $7,500, and low-risk issues $1,000. Security researchers who have successfully disclosed at least one critical, two high, four medium, or seven low-severity vulnerabilities will qualify to seek an invitation. However, GitHub has yet to specify the temporal window required to achieve these benchmarks, nor does fulfilling these thresholds guarantee automated admission.
Stemming the Influx of Low-Quality Submissions
GitHub aims to diminish the influx of superficial, automatically generated submissions, expedite the triage of high-quality disclosures, and foster closer collaboration with vetted researchers. Additional restrictions will target contributors with low HackerOne Signal scores, limiting them to a maximum of four initial submissions, though GitHub has not yet articulated the precise rating threshold.
The Impact of AI-Generated Reports
These structural changes emerge alongside the rapid proliferation of artificial intelligence tools capable of swiftly analyzing source code and generating vast quantities of hypothetical findings. While such systems empower researchers and internal security teams to audit repositories with greater frequency, they simultaneously generate an overwhelming volume of spurious or unverified reports. Previously, the curl open-source project suspended cash bounties entirely following a deluge of low-grade, AI-assisted reports.
Strict Standards for AI Usage
While GitHub does not prohibit the employment of AI in security research, it mandates that researchers independently reproduce their findings, substantiate the operational impact, and strictly adhere to program policies. A plausible narrative alone will no longer suffice to secure a payout: reports must provide a functional proof of concept, account for system architecture, and demonstrate tangible risk.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.