What changed (and the short version)
Starting July 27, 2026, GitHub dramatically reduced payments in its public bug bounty program and moved the fattest checks behind an invite-only door. If you filed a report before that date, don’t fret — those submissions will keep the old payout terms. Everything after the cutoff moves to new fixed tiers and lower public rewards.
In plain speak: GitHub swapped flexible reward ranges for fixed payouts, shrunk public awards by roughly half, and put the higher-end rewards in a private, invite-only VIP tier.
Numbers, rules, and why people are grumpy (and a little amused)
Here’s the new public payout schedule — short, blunt, and no more mysterious ranges:
- Low: $250 (previously hundreds to a couple thousand)
- Medium: $2,000 (previously a few thousand to $10,000)
- High: $5,000 (previously up to $20,000)
- Critical: $10,000 (previously $20,000+)
Meanwhile, the private VIP program (by invitation only) pays noticeably more: $1,000 for low, $7,500 for medium, $20,000 for high, and $30,000 or higher for critical reports. To even be considered for that velvet rope you need proven chops — the stated thresholds are something like one critical, two high, four medium, or seven low reports — though GitHub hasn’t made the time window or guaranteed-invite rules crystal clear yet.
GitHub says the change is meant to reduce triage noise, get faster responses to quality reports, and let their security engineers work more closely with top researchers. Their message: quantity won’t buy you higher payouts — better, rarer findings will.
There are a few other practical details worth noting:
- Reports already filed before the July 27 cutoff keep the old terms.
- GitHub may still hand out discretionary bonuses for exceptional work, but the baseline is now fixed.
- Newer or lower-signal researchers may face limits: the program will cap initial submissions for some researchers (you may get only a few trial reports before being limited).
Why the change? Welcome to the era of cheap candidate reports.
Generative tools and specialized vulnerability models have made it easy to churn out potential issues. That’s great for automation, but it also floods maintainers with low-quality or duplicate findings that eat time. Big tech companies are increasingly using automated agents to scan repos, validate issues, and push fixes before an external report ever arrives — which changes what a bounty program actually needs to reward.
We’ve already seen signs of this shift in the wild. Some maintainers temporarily paused or reworked cash bounties after the confirmed-vulnerability rate plunged when AI-generated submissions spiked. In one notable case, a long-running project stopped paying cash bounties, took a short break to rework its approach, and then saw submission quality rebound once the program rules were altered.
That explains the logic behind reduced public payouts and a tighter, invite-only tier: prioritize speed and higher-value collaboration with a smaller set of trusted researchers, and push routine noise out of the public channel.
Trade-offs and who loses — or wins
- Pros: Faster responses for top researchers, clearer payout expectations, fewer duplicate or junk reports clogging triage workflows.
- Cons: New or less-established researchers face a tougher entry path — fewer trial reports and smaller public rewards make learning the program and improving harder. The invite-only model also concentrates access to the people who already succeeded, which can reduce the diversity of perspectives hitting the platform.
Bottom line: this is a pragmatic move disguised as a spreadsheet. GitHub wants fewer low-signal reports and stronger partnerships with a smaller set of researchers. That helps their internal teams move faster, but it also raises the bar for people trying to break in.
In short: if you’re a veteran bug hunter with a track record, you might like the VIP speed lane. If you’re a hungry newcomer, expect a stricter audition and smaller public payouts while you build reputation.