GitHub Cuts Bug Bounty Payouts Amid AI Report Surge
GitHub is restructuring its bug bounty program, slashing payouts for public submissions while creating a new VIP tier with substantially higher rewards. The move directly addresses what the company calls a surge of low-effort and AI-generated vulnerability reports clogging the platform’s review pipeline.

The Two-Tier System Launches July 27

Starting July 27, the Microsoft-owned code repository is implementing a fundamental shift in how it compensates security researchers. Public submissions now face significantly reduced payouts. A new invite-only VIP program rewards proven contributors with substantially higher compensation.

The message is clear: GitHub wants fewer, higher-quality reports from trusted researchers rather than a flood of low-effort submissions from newcomers.

Public Program Payouts Drop Sharply

Researchers in the public program will see meaningful cuts across all severity levels:

Severity Level Previous Max New Max Change
Low $1,000 $250 75% cut
Medium $5,000 $2,000 60% cut
High $20,000 $5,000 75% cut
Critical $30,000 $10,000 67% cut

New researchers face additional friction. GitHub will impose submission caps until they demonstrate a track record of producing quality reports. The message to newcomers is unmistakable: prove yourself first, or expect limited opportunities.

Why GitHub Made This Decision

GitHub attributes the restructuring to a fundamental problem: too many low-quality submissions, many of them generated or assisted by AI tools. These reports consume review resources without identifying genuine threats.

Catherine Cassell, a product security engineer at GitHub, explained the rationale directly: These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.

This overhaul follows earlier tightening earlier this year, when GitHub warned against AI-assisted submissions and raised report quality standards. The new structure doubles down on that messaging.

The VIP Program: Rewards for Proven Researchers

Not all researchers face cuts. An invite-only VIP program offers dramatically higher compensation:

Severity Level VIP Payout
Low $1,000
Medium $7,500
High $20,000
Critical $30,000 and up

Entry to this tier requires credentials. Researchers must submit either one accepted critical vulnerability or seven accepted low-severity findings to qualify. This creates a clear incentive structure: establish credibility in the public program, then graduate to higher-paying work.

The Broader Strategy

GitHub’s gamble is straightforward: concentrated effort from skilled researchers beats dispersed effort from many casual hunters. A single critical vulnerability report from a vetted expert likely requires less review time and produces more actionable security information than ten low-effort AI-generated submissions.

The company also signaled continuity. Reports already in the backlog will be assessed under the previous payout structure, giving existing submissions a grace period and preventing sudden financial surprises for researchers in flight.

This move reflects a broader industry tension. As AI-assisted tools become ubiquitous, platforms like GitHub face a choice: maintain open access and drown in low-quality noise, or create friction that filters for genuine expertise. GitHub chose the latter.

Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates