● News

GitHub Slashes Bug Bounty Payouts by Half for Public Program

July 24, 2026 · snewle
GitHub Slashes Bug Bounty Payouts by Half for Public Program

GitHub is implementing significant reductions to its public bug bounty program payouts starting July 27, 2026, cutting rewards by at least half across all severity levels. The platform is transitioning from flexible payment ranges to fixed amounts, with critical vulnerabilities now earning researchers a flat $10,000 instead of the previous $20,000-$30,000 range.

What Are the New Payment Structures?

The revised payment structure introduces fixed amounts across all vulnerability categories. Low-severity issues will now pay $250, down from the previous range of $617-$2,000—a reduction of approximately 59%. Medium-severity vulnerabilities drop to $2,000 from $4,000-$10,000, while high-severity bugs will earn $5,000 instead of $10,000-$20,000. Critical vulnerabilities see their maximum payout cut from over $30,000 to a fixed $10,000.

GitHub maintains that fixed sums will make the bug bounty program more transparent and simplify report processing. The company stated that it can still award additional bonuses for particularly valuable discoveries. According to GitHub representatives, “More reports does not mean more money. Better quality work brings more money.”

How Does the VIP Program Work?

Alongside the public program cuts, GitHub is establishing a permanent closed VIP bug bounty program offering substantially higher rewards. VIP participants will receive $1,000 for low-severity bugs, $7,500 for medium-level issues, $20,000 for high-severity vulnerabilities, and at least $30,000 for critical bugs.

Researchers can qualify for VIP program invitations by reporting at least one critical vulnerability, two high-severity issues, four medium-severity problems, or seven minor vulnerabilities. However, GitHub has not specified the timeframe for achieving these requirements or whether meeting them guarantees an invitation. The company promised to publish detailed criteria later on the program’s HackerOne page.

What Additional Requirements Face Researchers?

The payment changes do not affect reports submitted before July 27, 2026, or submissions already in the review queue. However, GitHub will require researchers to meet a minimum HackerOne Signal score, though the specific threshold remains undisclosed. Those falling below this benchmark will be limited to submitting only four trial reports, potentially creating barriers for newcomers with limited margin for error in initial bug severity assessments.

These modifications continue policy tightening that began in May 2026, when GitHub announced requirements for working proof-of-concept code, confirmed vulnerability impact information, independent result verification, and strict adherence to program terms including eligible targets and bug types. While GitHub permits AI tool usage for vulnerability discovery, researchers must independently reproduce and verify all AI-generated findings, emphasizing that “tools don’t matter—the quality of work is important.”

Source: Xakep