GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub is cutting public bug bounty payouts by at least half at every severity level, starting July 27, 2026. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more.
Intelligence analysis by Llama

GitHub is reducing public bug bounty payouts and moving top rewards to its VIP tier, starting July 27, 2026. The changes aim to reduce noise and give established researchers faster responses, higher rewards, and closer access to its security engineering team.
Imagine you're a detective trying to find bugs in code. GitHub is changing the way it pays people for finding bugs. Instead of paying more for finding more bugs, it's paying more for finding better bugs. This might make it harder for new people to find bugs and get paid, but it might also make it easier for good detectives to find the really important bugs.
Analysis
GitHub's Shift in Bug Bounty Strategy
GitHub's decision to cut public bug bounty payouts and move top rewards to its VIP tier is a significant shift in its bug bounty strategy. The company aims to reduce noise and give established researchers faster responses, higher rewards, and closer access to its security engineering team. This move may impact researchers and maintainers, as they will need to adapt to the new payout structure and potentially face increased competition from AI-generated reports.
The Rise of AI-Generated Reports
The rise of AI-generated reports is a significant challenge for bug bounty programs. AI can flood maintainers with junk reports, but it can also make capable researchers faster and let internal teams examine more code, more often. A plausible-looking candidate finding is becoming abundant, but reliable exploits, product-specific attack chains, or findings that cross boundaries the vendor misunderstood remain scarce.
The Impact on Researchers and Maintainers
The changes may impact researchers and maintainers, as they will need to adapt to the new payout structure and potentially face increased competition from AI-generated reports. For a new HackerOne researcher, a four-report program limit leaves little room for mistakes, unfamiliarity with GitHub's security model, or a legitimate finding that is initially scored below expectations. The invite-only structure also concentrates GitHub's closest researchers, making it harder for new researchers to break in.
Key points
- GitHub is cutting public bug bounty payouts by at least half at every severity level, starting July 27, 2026.
- Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more.
- The changes aim to reduce noise and give established researchers faster responses, higher rewards, and closer access to its security engineering team.
The changes may lead to a more efficient bug bounty program, with established researchers producing higher-quality reports and internal teams examining more code, more often. This could result in faster and more reliable bug fixes, improving the overall security of GitHub's codebase.
The changes may suppress automated noise, but they can also make entry harder for capable researchers without an established HackerOne history. This could lead to a decrease in the number of new researchers participating in the program, potentially reducing the diversity of perspectives and ideas.



