GitHub slashes public bug bounty payouts as AI report flood buries its security team
Jump to main content
Search
REG AD
Dev ops
GitHub slashes public bug bounty payouts as AI report flood buries its security team
Code shack also putting new limits on first-time researchers, and reserving the biggest rewards for a hand-picked group of proven hunters
Carly Page
Carly<br>Page
Published<br>thu 23 Jul 2026 // 16:15 UTC
GitHub has decided that, if everyone with an AI chatbot can file a bug bounty report, it may as well stop paying them like seasoned security researchers.<br>Starting July 27, the Microsoft-owned code forge is overhauling its bug bounty program with a two-tier system that cuts rewards for public submissions while dangling much fatter payouts to a new invite-only group of researchers with proven track records.<br>At the same time, newcomers will find themselves capped on how many reports they can submit until they've demonstrated they can produce something worth reading.
REG AD
The Microsoft-owned biz says that the shake-up is a response to the flood of low-effort and AI-generated reports now accompanying many bug bounty programs. Rather than paying more people to file more reports, GitHub wants to spend more on researchers who've proved they can find the real thing. Cathering Cassell, product security engineer at GitHub. “These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.”
REG AD
For researchers sticking with the public program, a low-severity finding that previously earned between $500 and $1,000 will now bring in $250. Medium bugs top out at $2,000 instead of $5,000, high-severity flaws have been cut from as much as $20,000 to $5,000, and the maximum reward for a critical vulnerability falls from $30,000 to $10,000.
MORE CONTEXT
GitHub ponders kill switch for pull requests to stop AI slop
GitHub cuts short offer to burn repos on CD after mockery ensues
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
Holy git! Microsoft code-sharing site suffers downtime, despite move to Azure
The highest rewards are now reserved for GitHub's new invite-only VIP program. There, low-severity findings are worth $1,000, medium bugs $7,500, high-severity issues $20,000, and critical vulnerabilities at least $30,000.<br>Entry isn't open to everyone. GitHub says invitations will be based on a proven history of valid reports, with researchers needing anything from one accepted critical vuln to seven accepted low-severity findings to qualify.<br>GitHubb is also enabling HackerOne's "signal requirement," limiting how many reports new researchers can submit before they've established a history of legitimate findings. It says genuine newcomers will still have up to four opportunities to prove themselves, while reports already sitting in the backlog will continue to be assessed under the previous payout structure.<br>The overhaul follows changes GitHub introduced earlier this year that tightened report-quality requirements and warned researchers against flooding the platform with AI-assisted submissions.<br>GitHub is betting that fewer reports, from researchers with a proven track record, will do more for security than an ever-growing pile of AI-assisted submissions waiting for someone to read them. ®
bug bounty<br>devops<br>github
REG AD
AI and ML
Codeberg gives vibe-coded projects the toss, promotes human FLOSS
AI no longer welcome in human-focused community
Systems
AMD attacks the rack with Helios systems that rival Nvidia's
Spec for spec, the House of Zen's first rack-scale AI compute platform is bigger and faster than Nvidia's Vera Rubin by nearly every metric, but that's only on paper
Gobi X: Creating more energy for AI, not taking it from society
PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around
Patches
Year-long Russian attacks infect users as soon as they look at an email
Phishing for dummies
columnists
Airbus takes flight from AWS. What happens next is critical
Which way to the Land of the Free again?
DEVOPS
Model Context Protocol prepares to break with its stateful past
Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog
MOST POPULAR
columnists
Airbus takes flight from AWS. What happens next is critical
off-prem
Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five
security
Linux kernel team publishes 432 CVEs in two days
AI AND ML
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
off-prem
AWS customer learns the hard way how even the smallest oversight can be mission-critical
AI
AI and ML
Codeberg gives vibe-coded projects the toss, promotes human FLOSS
AI no...