GitHub has announced major changes to its bug bounty program, cutting public vulnerability rewards by at least 50% across nearly every severity level starting July 27, 2026, while increasing incentives for trusted researchers through a permanent invite-only VIP program.

Reports submitted before the deadline, including those already waiting in GitHub’s triage queue, will still be rewarded under the previous payout structure.

Under the new fixed payment model, low-severity vulnerabilities will pay $250 instead of the previous $617–$2,000, medium findings will receive $2,000 instead of $4,000–$10,000, high-severity bugs will pay $5,000 rather than $10,000–$20,000, and critical vulnerabilities will now earn a fixed $10,000, down from $20,000–$30,000 or more. GitHub says the simplified payouts will reduce uncertainty and speed up the review process, although exceptional reports may still receive discretionary bonuses.

At the same time, GitHub is expanding its invite-only VIP bug bounty program, where payouts remain significantly higher. Researchers in the program can earn $1,000 for low-severity findings, $7,500 for medium, $20,000 for high, and $30,000 or more for critical vulnerabilities.

To become eligible, researchers must report at least one critical, two high, four medium, or seven low-severity vulnerabilities. GitHub has not specified the timeframe for meeting these requirements or whether qualifying automatically guarantees an invitation, saying additional details will be published on its HackerOne program page.

The company says the changes are designed to improve report quality rather than reward submission volume. As GitHub explained, researchers will benefit more from submitting well-validated, high-impact vulnerabilities than from filing large numbers of reports.

READ
WhatsApp Begins Rolling Out Full Username Feature to More Users

The announcement comes as artificial intelligence is rapidly changing the vulnerability research landscape. GitHub acknowledged that AI-assisted security research is welcome but emphasized that researchers remain responsible for verifying every finding before submission.

Just one day before GitHub’s announcement, Google unveiled Gemini 3.5 Flash Cyber, a specialized AI model built to identify, validate, and even help patch software vulnerabilities. According to Google, the model discovered 55 confirmed security issues in Chrome’s V8 JavaScript engine during internal testing, outperforming both the standard Gemini 3.5 Flash model and Claude Opus 4.6. Google also claimed the system identified remote code execution vulnerabilities and generated reliable proof-of-concept exploits in internal security testing, although those results have not been independently verified.

The growing use of AI is already affecting bug bounty programs. Earlier this year, curl maintainer Daniel Stenberg ended the project’s cash bug bounty after being overwhelmed by AI-generated reports with a very low confirmation rate. After the project later returned to HackerOne, submission volume nearly doubled, and the quality of reports improved significantly, with many appearing to be AI-assisted but carefully validated.

GitHub believes verified vulnerabilities with demonstrated real-world impact will become increasingly valuable as AI makes it easier to generate large numbers of potential findings. While automated tools can quickly identify possible security issues, proving exploitability, understanding product-specific attack chains, and delivering actionable reports remain the areas where experienced human researchers provide the greatest value.

READ
AWS Glitch Shows Estimated Bills of Up to $1.5 Trillion for Customers Worldwide

The restructuring follows GitHub’s earlier policy updates introduced in May 2026, which raised submission standards by requiring proof-of-concept exploits, clear impact demonstrations, and stronger validation before reports are accepted. The company says AI can accelerate security research, but the responsibility for delivering accurate, reproducible, and high-quality reports ultimately remains with the researcher.


Buy ExpressVPN with PayPal or Credit Card

Advertisement