GitHub slashes public bug bounty payouts as AI report flood buries its security team
GitHub is overhauling its public bug bounty programme from 27 July 2026, cutting payouts for openly submitted reports while creating a new invite-only tier with much higher rewards for researchers with a proven track record. The Microsoft-owned company says the change is a response to a surge of low-quality and AI-generated submissions that have overwhelmed its security team, and it hopes redirecting funds towards vetted researchers will improve the quality of reports it receives.
Under the revised public programme, low-severity findings drop from $500–$1,000 to $250, medium-severity rewards fall from a $5,000 cap to $2,000, high-severity payouts are cut from up to $20,000 to $5,000, and critical vulnerabilities now max out at $10,000 rather than $30,000. The new VIP tier, by contrast, pays up to $1,000, $7,500, $20,000 and at least $30,000 respectively across the same severity bands, with entry based on a history of accepted reports. GitHub is also adopting HackerOne's "signal requirement" to cap how many reports newcomers can submit before proving themselves, though it will allow up to four attempts and will honour the old payout rates for reports already in its backlog.
- GitHub cuts public bug bounty rewards from 27 July 2026
- New invite-only tier offers much higher payouts for proven researchers
- Move aims to curb flood of low-quality, AI-generated reports