Open-Source AI

GitHub Splits Its Bug Bounty Into VIP and Public Tiers

GitHub Splits Its Bug Bounty Into VIP and Public Tiers

GitHub Bug Bounty program artwork with the Octocat security theme

GitHub is rebuilding the economics of its bug bounty program around a blunt principle: you don’t earn more by submitting more, you earn more by submitting better. In a July 22 announcement, product security engineer Catherine Cassell laid out the biggest structural change to the program in years — a permanent invite-only VIP tier with dramatically higher payouts, a flattened public bounty table, and a new submission gate designed to filter out the flood of low-effort and AI-generated reports.

The timing is not subtle. Reports submitted on or after July 27, 2026 will be assessed under the new structure; everything already in the queue is grandfathered under the old rates. Researchers sitting on findings have a very short window to decide which regime they want to be judged by.

Two bounty tables, one big gap

The headline change is the split. The new VIP program pays $1,000 for low-severity findings, $7,500 for medium, $20,000 for high, and $30,000+ for critical vulnerabilities. The restructured public program pays $250, $2,000, $5,000 and $10,000 for the same severity levels — meaning a critical bug is worth three times more inside the VIP tier, and a medium nearly four times more.

Qualification for VIP is published and mechanical rather than discretionary: one critical finding, two highs, four mediums, or seven lows gets you in, with the criteria to be posted on GitHub’s public HackerOne page. Beyond money, GitHub says VIP researchers get faster response times and a direct working relationship with its security engineering team.

The public table also moves from payout ranges to static, single-number rewards per severity. Cassell’s reasoning is that ranges “sound flexible, but in practice they create uncertainty for researchers and overhead for our team” — a quiet admission that haggling over where a bug lands inside a range has been burning triage time on both sides. Discretionary bonuses remain for exceptional work.

The AI-slop problem gets a gate

The most industry-significant piece is the new signal requirement. GitHub is implementing a HackerOne signal threshold on the public program specifically “to reduce the volume of low-effort and AI-generated reports.” Researchers below the threshold get up to four initial submissions to establish a track record before the limit tightens.

That makes GitHub one of the highest-profile programs to formally name AI-generated reports as a problem worth engineering against: LLM-generated vulnerability reports — plausible-sounding, mass-produced, and usually wrong — crowd the same queues real findings sit in, and Cassell’s post cites “an increasing queue” as the direct trigger for the changes. The company had already tightened standards once this year in its “Raising the bar” update, which reworked how low-risk findings are rewarded. This announcement finishes that arc by changing who can submit at volume in the first place.

The four-submission runway is the interesting design choice. A hard reputation wall would lock out newcomers entirely — a real cost, since career-defining first finds are part of how the research pipeline replenishes. Four attempts is enough for a genuine discovery to land, and roughly zero cover for someone spraying generated reports.

What it means for researchers

For established researchers, the calculus improves sharply: a track record now compounds into materially better rates and priority handling, formalized in GitHub’s bounty program rather than handled ad hoc. For newcomers, the message is to make the first shots count. And for casual submitters who treated the public program as a lottery, the $250 low-severity payout — down from range-based rewards — is a deliberate discouragement.

The unresolved tension is visible in the public-tier cuts. GitHub frames the public program as “a place to explore” and a feeder into VIP, but a $10,000 public critical for one of the most valuable targets on the internet will strike some researchers as light — particularly when the same bug pays $30,000+ a tier up. Whether that gap reads as an incentive ladder or a paywall will depend entirely on how attainable the VIP criteria prove in practice. GitHub says it will keep paying quickly and communicating clearly, and points researchers toward direct engagement at conferences like DEF CON. The program that helped normalize bug bounties a decade ago is now betting that fewer, better-paid researchers beat an open floodgate.

We may earn commission from affiliate links at no extra cost to you. Last updated: Jul 24, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.