The Two-Tier System Launches July 27
Starting July 27, the Microsoft-owned code repository is implementing a fundamental shift in how it compensates security researchers. Public submissions now face significantly reduced payouts. A new invite-only VIP program rewards proven contributors with substantially higher compensation.
The message is clear: GitHub wants fewer, higher-quality reports from trusted researchers rather than a flood of low-effort submissions from newcomers.
Public Program Payouts Drop Sharply
Researchers in the public program will see meaningful cuts across all severity levels:
| Severity Level | Previous Max | New Max | Change |
|---|---|---|---|
| Low | $1,000 | $250 | 75% cut |
| Medium | $5,000 | $2,000 | 60% cut |
| High | $20,000 | $5,000 | 75% cut |
| Critical | $30,000 | $10,000 | 67% cut |
New researchers face additional friction. GitHub will impose submission caps until they demonstrate a track record of producing quality reports. The message to newcomers is unmistakable: prove yourself first, or expect limited opportunities.
Why GitHub Made This Decision
GitHub attributes the restructuring to a fundamental problem: too many low-quality submissions, many of them generated or assisted by AI tools. These reports consume review resources without identifying genuine threats.
Catherine Cassell, a product security engineer at GitHub, explained the rationale directly: These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.
This overhaul follows earlier tightening earlier this year, when GitHub warned against AI-assisted submissions and raised report quality standards. The new structure doubles down on that messaging.
The VIP Program: Rewards for Proven Researchers
Not all researchers face cuts. An invite-only VIP program offers dramatically higher compensation:
| Severity Level | VIP Payout |
|---|---|
| Low | $1,000 |
| Medium | $7,500 |
| High | $20,000 |
| Critical | $30,000 and up |
Entry to this tier requires credentials. Researchers must submit either one accepted critical vulnerability or seven accepted low-severity findings to qualify. This creates a clear incentive structure: establish credibility in the public program, then graduate to higher-paying work.
The Broader Strategy
GitHub’s gamble is straightforward: concentrated effort from skilled researchers beats dispersed effort from many casual hunters. A single critical vulnerability report from a vetted expert likely requires less review time and produces more actionable security information than ten low-effort AI-generated submissions.
The company also signaled continuity. Reports already in the backlog will be assessed under the previous payout structure, giving existing submissions a grace period and preventing sudden financial surprises for researchers in flight.
This move reflects a broader industry tension. As AI-assisted tools become ubiquitous, platforms like GitHub face a choice: maintain open access and drown in low-quality noise, or create friction that filters for genuine expertise. GitHub chose the latter.
Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates



