Starting July 27, 2026, GitHub will implement significant changes to its bug bounty program, halving public payouts across all severity levels. While critical findings will now earn a fixed $10,000, the exclusive invite-only VIP tier will offer rewards of $30,000 or more.
Details of the New Bug Bounty Structure
Under the new structure, reports submitted before the implementation date will retain the previous payout terms. GitHub aims to reduce submission noise and provide swift responses, higher rewards, and closer collaboration with its security engineering team to seasoned researchers.
The revamped public program transitions from flexible payout ranges to fixed amounts: $250 for low, $2,000 for medium, $5,000 for high, and $10,000 for critical findings. According to The Hacker News, this represents a 50% reduction for medium to critical findings and a 59% decrease for low-severity reports compared to previous minimums.
VIP Tier and Qualification Criteria
The VIP tier offers payouts of $1,000 for low-severity, $7,500 for medium, $20,000 for high, and $30,000 or more for critical vulnerabilities. To qualify, researchers must report a minimum of one critical, two high, four medium, or seven low-severity vulnerabilities. However, the announcement does not specify a time frame for these conditions, nor does it guarantee an invitation based on these criteria.
GitHub has not disclosed the HackerOne Signal threshold required for participation, while HackerOne’s general policy permits new researchers up to four trial reports per program within a 30-day window.
Impact of AI and Future Prospects
As AI tools advance, they make identifying potential vulnerabilities more accessible, influencing the bug bounty landscape. GitHub’s announcement coincides with Google’s introduction of Gemini 3.5 Flash Cyber, a model designed to find and patch software vulnerabilities, initially available to governments and trusted partners.
AI enables internal teams to scan code and address issues before external reports are filed, potentially increasing the volume of submissions. While AI can generate numerous plausible findings, the challenge remains in triaging, validating, and contextualizing these reports.
GitHub’s adjustments may deter automated noise but could also restrict entry for adept researchers without a history on HackerOne. The move to a more selective, invite-only structure could enhance report quality and speed but may limit the diversity of perspectives on the platform.
In conclusion, GitHub’s policy shift reflects a broader trend in cybersecurity research, balancing the benefits of AI with the need for human expertise in complex vulnerability assessments. As the landscape evolves, both AI-assisted and traditional research methods will continue to play crucial roles in maintaining software security.
