Key Takeaways
- Starting July 27 2026, GitHub’s public bug‑bounty payouts are cut by roughly half: Low $250 (was $617‑$2,000), Medium $2,000 (was $4,000‑$10,000), High $5,000 (was $10,000‑$20,000), Critical $10,000 (was $20,000‑$30,000+).
- Researchers who file reports before that date keep the old payout terms, even if the reports remain in the triage queue.
- An invite‑only VIP tier offers higher, fixed rewards: Low $1,000, Medium $7,500, High $20,000, Critical $30,000 or more. Qualification requires at least one critical, two high, four medium, or seven low‑severity findings (no explicit time window stated).
- GitHub says the changes aim to reduce “noise,” give established researchers faster responses and higher rewards, and bring them closer to its security engineering team.
- The shift coincides with AI‑driven vulnerability discovery that can flood programs with low‑quality reports; GitHub retains discretionary bonuses for exceptional work and stresses that researchers remain responsible for verifying AI‑generated findings.
- HackerOne’s general rules still limit new researchers to four trial reports per program in a rolling 30‑day window, and GitHub may enforce a Signal threshold that caps initial submissions for researchers below it.
- The broader trend—illustrated by Google’s Gemini 3.5 Flash Cyber model and the curl project’s experience—shows AI can both increase junk reports and enable internal teams to validate and fix issues faster, making high‑impact, manually verified findings increasingly scarce.
Overview of GitHub’s Revised Bounty Structure
GitHub announced that, beginning July 27 2026, the public bug‑bounty program will replace its previous payment ranges with fixed amounts at each severity level. Low‑severity findings will now earn a flat $250, down from a prior range of $617‑$2,000. Medium reports will receive $2,000 (previously $4,000‑$10,000), High reports $5,000 (previously $10,000‑$20,000), and Critical reports $10,000 (previously $20,000‑$30,000+). The Hacker News calculated that these new rates represent roughly a 50 % reduction for Medium, High, and Critical findings and about a 59 % cut for Low‑severity reports when measured against the bottom of the old ranges.
Treatment of Pre‑Announcement Reports
Any vulnerability report submitted before the July 27 2026 cutoff will continue to be compensated under the legacy payout terms, even if the report remains in GitHub’s triage queue after the change takes effect. This grandfathering provision is intended to avoid disadvantaging researchers who had already invested time in analysis before the policy shift was announced. GitHub emphasized that the change does not retroactively affect rewards for work already completed.
Rationale Behind the Changes
GitHub stated that the primary goal of the redesign is to reduce the volume of low‑quality or duplicative submissions—often referred to as “noise”—while improving the experience for established contributors. By moving to fixed payments, the program removes uncertainty about potential rewards and cuts the administrative overhead associated with negotiating payout amounts within ranges. The company also pledged to grant discretionary bonuses for exceptional work that exceeds the baseline fixed amount, ensuring that truly outstanding research can still be recognized.
Details of the Invite‑Only VIP Program
Concurrent with the public program overhaul, GitHub introduced a permanent VIP tier that offers higher, fixed rewards: Low $1,000, Medium $7,500, High $20,000, and Critical $30,000 or more. Researchers can become eligible for this private program by demonstrating a track record of impactful findings—specifically, by reporting at least one critical, two high, four medium, or seven low‑severity vulnerabilities. The announcement did not specify a qualifying time window nor guarantee that meeting these thresholds automatically results in an invitation; GitHub said fuller criteria will be posted on its public HackerOne program page.
Interaction with HackerOne’s Signal and Submission Limits
GitHub indicated it will enforce a HackerOne Signal threshold to further filter incoming reports, though the exact value has not been disclosed. Researchers whose Signal falls below the cutoff will be limited to up to four initial submissions before facing additional scrutiny. This aligns with HackerOne’s general rule that new researchers receive four trial reports per program within a rolling 30‑day window. Consequently, newcomers have limited room for error or for submissions that may initially be mis‑scored, potentially raising barriers for talented researchers lacking an established reputation on the platform.
AI‑Generated Findings and the Evolving Threat Landscape
The policy update arrives amid a surge in AI‑assisted vulnerability discovery. Tools such as Google’s Gemini 3.5 Flash Cyber model—fine‑tuned to detect, validate, and patch software flaws—can be invoked repeatedly to scan large codebases without the cost of running larger frontier models each time. In internal tests, the model uncovered 55 unique confirmed V8 issues, outperforming baseline Gemini 3.5 Flash and Claude Opus 4.6. Google also reported using the model to identify remote‑code‑execution flaws in public APIs and a memory‑corruption bug in a sensitive production service within two hours, subsequently generating a 100 %‑reliable exploit that bypassed ASLR and W^X (though these results remain unverified by third parties).
How AI Augments Internal Security Workflows
Beyond external bug bots, AI agents can be embedded in development pipelines to provide repository context, project‑specific threat models, and tailored validation environments. Systems like OpenAI’s Codex Security can then test findings, generate proof‑of‑concept exploits, and suggest fixes that respect the system’s intended behavior. This enables continuous, commit‑level scrutiny rather than relying solely on periodic assessments or external reports. While AI does not replace the nuanced judgment of human penetration testers—particularly for chaining weaknesses across trust boundaries, spotting business‑logic flaws, or proving material impact—it significantly lowers the barrier for early detection and rapid remediation.
Lessons from the curl Project
The curl maintainer, Daniel Stenberg, terminated the project’s cash bug bounty at the end of January 2026 after the confirmed‑vulnerability rate dropped below 5 %, attributing the decline to an influx of AI‑generated junk reports. After switching back to HackerOne without cash rewards, curl saw report volume double compared to 2025, with a confirmed‑vulnerability rate of 15‑16 %. Stenberg observed that nearly every submission appeared AI‑assisted and, importantly, that the majority were now high quality. This case illustrates how removing financial incentives can suppress low‑effort spam while still attracting serious researchers who value reputation over immediate payout.
Implications for the Bug‑Bounty Ecosystem
Taken together, GitHub’s reduced public payouts, the introduction of a VIP tier, HackerOne’s submission limits, and the growing capability of AI‑driven scanners point to a broader shift: the ease of generating candidate findings is increasing, but the scarcity of reliably exploitable, context‑aware vulnerabilities remains. Signal requirements and lower public rewards may deter automated noise, yet they could also hinder entry for capable researchers lacking a proven HackerOne history. The invite‑only VIP model concentrates GitHub’s closest relationships among those who have already succeeded inside the program, potentially accelerating response times and improving report quality, but it may also narrow the diversity of perspectives examining the platform—a traditional advantage of open bounty programs.
Continued Emphasis on Researcher Responsibility
Despite the reliance on AI tools, GitHub reiterated that researchers remain accountable for reproducing and validating any findings generated by their automated aids. The company’s stance—“The tools don’t matter. The quality of the work does.”—underscores that while AI can accelerate discovery, the ultimate value lies in human judgment, creativity, and rigorous verification. As of July 22, GitHub’s public rewards page still displayed the legacy $20,000‑$30,000+ range for Critical reports, and its FAQ retained the prior VIP eligibility criteria (at least $20,000 earned and two reports submitted in the preceding two years) with the caveat that meeting those thresholds does not guarantee an invitation and that candidates are reviewed quarterly. This lag between announcement and documentation highlights the transitional nature of the program as GitHub rolls out the new structure over the coming months.

