GitHub changes bug bounty payouts as AI reports strain triage

GitHub source image for its bug bounty program.GitHub
GitHub source image for its bug bounty program.GitHub
Tools & Apps

GitHub is restructuring its bug bounty program on July 27, adding a permanent VIP tier, fixed public payouts, and a HackerOne signal requirement meant to reduce low-quality and AI-generated vulnerability reports.

GitHub's bug bounty rules change on July 27, 2026. The company is moving to fixed public payouts, creating a permanent invite-only VIP tier, and adding a HackerOne signal requirement after a rise in low-quality and AI-generated vulnerability reports.

For security researchers, the deadline is practical: reports submitted before July 27 stay under the previous payout structure, while reports submitted on or after that date are assessed under the new rules. For platform teams, the change is another sign that AI-assisted vulnerability reporting is forcing large programs to rethink incentives, triage, and access.

GitHub moves top rewards into a VIP lane

GitHub says the private VIP program is now a permanent part of its bug bounty structure. Qualified researchers will receive faster response times, closer collaboration with GitHub's security engineering team, and higher payouts than the public program.

The VIP payout table starts at $1,000 for low-severity findings, then moves to $7,500 for medium, $20,000 for high, and $30,000 or more for critical issues. GitHub says the criteria for qualifying will be published on its public HackerOne page, with eligibility tied to demonstrated finding quality rather than submission volume.

The initial qualification thresholds are explicit: one critical finding, two high findings, four medium findings, or seven low findings. That makes the program less attractive to high-volume automated reporting and more valuable for researchers who can repeatedly show impact.

Public payouts become fixed numbers

The public program is also changing. GitHub is replacing broad payout ranges with fixed public amounts: $250 for low severity, $2,000 for medium, $5,000 for high, and $10,000 for critical findings.

That is a meaningful reduction for researchers who previously targeted the upper end of GitHub's public bounty ranges. The Hacker News and Help Net Security both reported the same July 27 effective date and the same core shift: GitHub is lowering public reward ambiguity while reserving higher payouts for the invite-only tier.

GitHub says it will still be able to award discretionary bonuses for exceptional work. The practical reading is that public reports now need to be more carefully scoped, reproduced, and justified before submission, because payout upside is narrower unless a researcher qualifies for VIP status.

HackerOne signal becomes a gate

The new HackerOne signal requirement is aimed at reducing reports that do not show real security impact. GitHub says researchers below the signal threshold will receive up to four initial submissions while they establish a track record.

That still leaves room for new researchers with a genuine finding. It also makes speculative reports, weak proof-of-concept writeups, and automated issue dumps more expensive for the submitter. The change is not only about payment levels; it changes who can keep sending reports at scale.

GitHub's stated concern is not that AI can never help security research. The problem is triage load. If a program spends too much time rejecting theoretical, duplicate, or non-reproducible reports, strong findings wait longer and researcher trust drops.

What researchers should change now

Researchers should treat this as a documentation and targeting change. Before filing, confirm scope, demonstrate impact, include a reproducible proof of concept, and explain why the finding is not already covered by GitHub's ineligible list or a known issue.

Teams running their own bug bounty programs should watch the same pattern. AI can speed up reconnaissance and report drafting, but it also lowers the cost of weak submissions. Clear severity rules, proof standards, researcher reputation signals, and fast triage feedback are becoming part of the security surface.

The next milestone is July 27. After that, the public table is no longer a flexible range, and the best GitHub rewards move behind a quality bar.

Sources and methodology

This post uses GitHub's July 22 security blog as the primary source and cross-checks the effective date, payout structure, and AI-report context against Help Net Security and The Hacker News. Social posts and forum discussion were not used as evidence.