GitHub Cuts Bug Bounty Payouts by 50%, Moves Top Rewards to Invite-Only VIP Tier
GitHub will slash public bug bounty payouts by at least half across every severity level beginning July 27, 2026, replacing its flexible reward ranges with fixed payments and concentrating top-tier compensation behind an invite-only VIP program. Critical findings will drop from a previous range of $20,000–$30,000+ to a flat $10,000, while medium-severity reports fall from $4,000–$10,000 to $2,000 and high-severity bugs decline from $10,000–$20,000 to $5,000. Low-severity reports see the steepest cut, moving from $617–$2,000 to $250—a roughly 59% reduction. Reports submitted before July 27, including those currently sitting in GitHub's growing triage queue, will be honored under the previous payout terms. According to GitHub, the restructure is designed to cut down on low-quality submissions and reward demonstrated expertise, with the company stating: "You don't earn more by submitting more. You earn more by submitting better."
The new VIP tier, reserved for proven researchers, sets payouts at $1,000 (low), $7,500 (medium), $20,000 (high), and $30,000 or more (critical), alongside faster triage, priority access, and closer collaboration with GitHub's security engineering team. Qualification requires reporting at least one critical, two high, four medium, or seven low-severity vulnerabilities through GitHub's HackerOne program—though the announcement does not specify the time window for meeting those thresholds nor whether meeting them guarantees an invitation. GitHub has also declined to disclose its enforcement threshold for HackerOne's Signal reputation metric, though it confirmed that researchers falling below the threshold will be limited to four initial submissions. Researchers vetting their own exposure before filing reports can run a quick email breach checker to confirm their researcher accounts haven't been compromised, or verify their connection integrity using a DNS leak test.
The timing of GitHub's announcement aligns with a broader shift in vulnerability discovery driven by AI. One day prior, Google unveiled Gemini 3.5 Flash Cyber, a lightweight model fine-tuned to identify, validate, and patch software vulnerabilities. Initially available only to governments and trusted partners through Google's CodeMender code-security agent, the model is designed for repeated invocation across large codebases without consuming resources from a larger frontier model. Google has positioned it for continuous repository scans, pre-launch code review, and commit-pipeline integration—capabilities that mirror the kind of internal automation GitHub's restructured program appears designed to absorb. As AI-driven candidate findings flood the bug bounty pipeline, platforms are responding by raising quality bars and concentrating payouts among researchers whose track records reduce triage overhead. Researchers and defenders looking to harden their own environments can audit their attack surface with an privacy checkup or validate web-facing configurations using an SSL/TLS checker.