Today is the cutover. Any report submitted to GitHub’s bug bounty program on or after July 27, 2026 is assessed under the restructured rules the company announced last week — new static payouts, a permanent invite-only VIP tier, and a HackerOne signal requirement on the public program. Reports filed before today are grandfathered under the old structure, so the backlog is safe. But from this point forward, the economics of hunting bugs on GitHub have changed, and the smart response is to change how you hunt. This guide walks through what the new structure actually rewards and how to position your next report on either side of the VIP line.
The new payout tables, side by side
GitHub product security engineer Catherine Cassell laid out both tables in the official announcement. The public program moves from payout ranges to a single static number per severity:
| Severity | Public program | VIP program |
|---|---|---|
| Low | $250 | $1,000 |
| Medium | $2,000 | $7,500 |
| High | $5,000 | $20,000 |
| Critical | $10,000 | $30,000+ |
Two things jump out. First, the VIP multiplier is steep — 4x on every tier and uncapped at critical. A researcher who lands VIP status is playing a fundamentally different game than one grinding the public queue. Second, static public payouts remove the negotiation ambiguity that ranges created. You know the number before you write the report, and GitHub retains discretionary bonuses for work that goes beyond the table.
GitHub is candid about the trade: public rates were adjusted specifically to fund the shift toward “quality of relationships and findings over quantity of reports.” If your strategy was volume — many low-severity reports across GitHub’s surface — the new public table pays you less for it by design.
How the VIP qualification math works
The VIP program is permanent, private, and invite-only, but the path in is published rather than mysterious. Per the announcement, you qualify by demonstrating consistent quality through at least one of four thresholds: one critical finding, two high findings, four medium findings, or seven low findings. Full criteria live on GitHub’s public HackerOne page.
That math creates a clear strategic hierarchy. One critical is the express lane. Two highs is the realistic target for a skilled researcher over a season of focused work. The four-medium and seven-low paths exist, but they force the exact behavior the program is de-emphasizing — accumulating smaller findings — at reduced public rates while you climb.
The practical read: pick a deep target area and stay there. GitHub explicitly frames VIP as a home for “researchers who invest deeply in understanding GitHub,” with higher payouts, faster response times, and a direct working relationship with its security engineering team. Depth is now the compensated skill. Surface-level scanning across the platform was already low-yield; under the new table, it is decisively the wrong strategy.
The signal requirement: what newcomers need to know
The most consequential change for new researchers is the HackerOne signal threshold on the public program. Signal is HackerOne’s reputation metric — it rises with valid, triaged reports and falls with duplicates, informatives, and spam. Researchers below GitHub’s threshold now get a limited number of submissions while they establish a track record: up to four initial reports.
GitHub’s framing is that this is a filter for noise, not a wall against newcomers — the stated motivation is cutting “low-effort and AI-generated reports” that have been flooding the queue industry-wide. But the mechanics matter if you are starting out. Four submissions is enough runway for a genuine finding, and exactly zero margin for speculative ones.
If you are below the threshold, treat those four slots as non-renewable capital. Do not spend them on theoretical issues, self-XSS, or anything the program’s prior quality guidance already classifies as low-value — GitHub telegraphed this direction in its earlier “Raising the bar” post, which tightened standards around shared-responsibility boundaries and low-risk findings. A single well-documented, reproducible, clearly scoped vulnerability does more for your signal than four maybes. And if you have general HackerOne history from other programs, your existing signal may already clear the bar — check before assuming you are capped.
What a competitive report looks like now
Static payouts and a quality filter shift where the marginal effort goes. Under a range system, negotiation and severity argument had value. Under static tables, the leverage moves entirely to severity classification and impact demonstration. Concretely, that means three things for the report itself.
Prove maximum realistic impact. The difference between a $2,000 medium and a $5,000 high — or a $7,500 and $20,000 gap at VIP rates — is your exploitation chain, not adjectives. Show the pivot, quantify the blast radius, demonstrate the data exposure.
Make triage effortless. Faster response times are one of GitHub’s stated investments, and reports that reproduce cleanly on the first pass are the ones that benefit. Include exact requests, minimal proof-of-concept steps, and environment details up front.
Respect the scope boundaries GitHub has been publishing. The program has spent this year clarifying what it considers shared-responsibility territory versus platform vulnerability. Reports that ignore those boundaries are precisely the noise the signal requirement exists to filter — and under the new rules, they cost you future submission slots, not just time.
The cutover checklist
If you have active research on GitHub targets, here is where things stand as of today. Anything already submitted is honored under the old structure, so there is no reason to withdraw or resubmit. Anything you submit from now on hits the new tables — which means severity potential should now drive your prioritization queue more aggressively than before. Mediums that were borderline-worth-writing-up at the old range midpoints pay a flat $2,000 now; a high pays 2.5x that; getting two highs pays forward into a 4x payout tier permanently.
The bigger picture is that GitHub is following the same arc as other mature bounty programs: separating a professional tier from an open funnel, and using platform reputation as the gate between them. The public program is now explicitly a feeder — “a place to explore,” as Cassell puts it — and the real money sits behind demonstrated consistency. For researchers willing to specialize in GitHub’s stack, the ceiling just rose substantially. For everyone else, the floor got firmer and the door got narrower, and the four-submission runway is the whole tryout.
