Next chapter: Restructuring GitHub's bug bounty program - The GitHub Blog
Try GitHub Copilot CLI
Attend GitHub Universe
Search
Catherine Cassell·@plutonianfern
July 22, 2026
4 minutes
Share:
The security research community makes GitHub safer for everyone. That’s the simple idea behind our bug bounty program.
For more than a decade, researchers from around the world have helped us find and fix vulnerabilities before they could be exploited, and we’ve worked hard to be a program worth their time.
Today, we’re sharing some meaningful changes to how the program works. These decisions comes after months of reflecting on our program, analyzing what’s happening across the industry, and thinking about researcher experience.
What’s changed and why
The program is facing an increasing queue. We have already made adjustments to accommodate the rise in new researchers and the acceleration in efforts of researchers we’ve been working with. We shared these changes in a recent blog post.
These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.
Introducing a permanent VIP program
We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. VIP researchers get higher payouts, faster response times, and a closer working relationship with our security engineering team. The goal is to create a space where the researchers who invest deeply in understanding GitHub can work with us directly and get an experience that reflects the effort they put in.
VIP program bounty table:
Severity Payout Low $1,000 Medium $7,500 High $20,000 Critical $30,000+
How to qualify: We’ll publish clear criteria on our public HackerOne page. The path in is built around demonstrated, consistent quality. To qualify, you must accomplish at lea st one of the following:
One critical finding
Two high findings
Four medium findings
Seven low findings
The core shift here is in what we’re incentivizing: you don’t earn more by submitting more. You earn more by submitting better.
A restructured public bounty table
To commit ourselves to the changes in our prioritization above, we also must make changes that enable it. We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range. Ranges sound flexible, but in practice they create uncertainty for researchers and overhead for our team. Static payouts set clear expectations on both sides, and we retain the ability to award discretionary bonuses for work that goes above and beyond.
Our new public program bounty table:
Severity Payout Low $250 Medium $2,000 High $5,000 Critical $10,000
This adjustment will enable us to provide more tailored attention and higher rewards to our VIP program, while still enabling our public program to be a place to explore and serve as a feeder into the VIP program.
Raising the signal requirement
To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program. Researchers who don’t yet meet the signal threshold will have a limited number of allowed submissions while they establish a track record.
This isn’t a wall against new researchers. HackerOne’s platform gives researchers who don’t meet the threshold up to four initial submissions, which is enough runway for a newcomer with a genuine finding to demonstrate their skills. We want to remain accessible to the full security research community; we just need a baseline that keeps the program workable for everyone.
What stays the same
Our commitment to rewarding real security research isn’t changing. We’ll continue to pay out quickly, communicate clearly, and treat researchers as the partners they are.
Reports submitted before these changes take effect will be honored under the previous bounty structure. We’re grandfathering the backlog so that only reports made on or after July 27, 2026 will be assessed with the new structure.
Looking ahead
This is one part of the broader evolution we’re working through. Alongside the bounty restructuring and the VIP program, we’re investing in faster response times, clearer severity reasoning, and more community engagement. Great working relationships are built on more than a pay table. You can engage directly with us at conferences like DEFCON and you’ll hear from us through ongoing outreach. We look forward to joining the researcher community at security conferences, building relationships, and continuing to explore ways to make our bug bounty program one that rewards the kind of deep, thoughtful...