Next chapter: Restructuring GitHub's bug bounty program
GitHub is restructuring its bug bounty program to prioritize quality over quantity, introducing a permanent VIP program for top researchers and adjusting public program rates to focus on high-impact work.
Intelligence analysis by Llama

GitHub is overhauling its bug bounty program to prioritize quality over quantity, introducing a VIP program for top researchers and adjusting public program rates.
GitHub is changing its bug bounty program to focus on quality over quantity. It's creating a special program for top researchers and adjusting the way it pays out for bug reports. This will help GitHub find and fix vulnerabilities more efficiently and reward serious researchers for their work.
Analysis
A Shift in Priorities
GitHub's bug bounty program has been a cornerstone of the company's security efforts for over a decade. However, as the program has grown, so has the volume of reports, making it increasingly difficult for researchers to stand out. To address this, GitHub is introducing a permanent VIP program for qualified researchers who consistently deliver high-quality, high-impact work. This program will offer higher payouts, faster response times, and a closer working relationship with GitHub's security engineering team.
A New Bounty Table
The public bounty table is also undergoing a significant change. GitHub is introducing static payouts for each severity level, rather than a wide range. This will provide clear expectations for researchers and reduce uncertainty. The new bounty table will be as follows:
Severity Payout
Low $250
Medium $2,000
High $5,000
Critical $10,000
Raising the Signal Requirement
To reduce the volume of low-effort and AI-generated reports, GitHub is implementing a HackerOne signal requirement on the public program. Researchers who don't yet meet the signal threshold will have a limited number of allowed submissions while they establish a track record. This is not a wall against new researchers, but rather a baseline that keeps the program workable for everyone.
What Stays the Same
GitHub's commitment to rewarding real security research remains unchanged. The company will continue to pay out quickly, communicate clearly, and treat researchers as partners. Reports submitted before the changes take effect will be honored under the previous bounty structure. The backlog will be grandfathered, and only reports made on or after July 27, 2026, will be assessed with the new structure.
Looking Ahead
This is one part of the broader evolution GitHub is working through. Alongside the bounty restructuring and the VIP program, the company is investing in faster response times, clearer severity reasoning, and more community engagement. Great working relationships are built on more than a pay table. GitHub looks forward to joining the researcher community at security conferences, building relationships, and continuing to explore ways to make its bug bounty program one that rewards the kind of deep, thoughtful research it cares about most.
Key points
- GitHub is restructuring its bug bounty program to prioritize quality over quantity.
- A permanent VIP program will be introduced for top researchers.
- The public bounty table will be adjusted to provide clear expectations for researchers.
- A HackerOne signal requirement will be implemented to reduce low-effort and AI-generated reports.
- Reports submitted before the changes take effect will be honored under the previous bounty structure.
The changes to the bug bounty program will likely attract more serious researchers and lead to a higher quality of submissions, ultimately making GitHub's security efforts more effective.
The new bounty table and signal requirement may deter some researchers from participating, potentially reducing the overall number of submissions and the quality of the research.
