What actually changed in GitHub's bug bounty program?
GitHub now operates a two-tier bug bounty system. The public program is open to everyone but pays less, with fixed payouts per severity ($250, $2,000, $5,000, and $10,000 for low to critical). The exclusive VIP tier is invite-only, with rewards roughly three to four times higher per valid report. This structure aims to better manage the growing volume and variable quality of submissions, which have increased dramatically due to the use of AI tools to generate vulnerability reports.
Why did GitHub make this move?
The rapid rise in AI-generated and low-effort reports overwhelmed GitHub’s previous bounty process, leading to more noise and slower reviews for genuine vulnerabilities. By creating a stricter entry barrier for the higher tier and more predictable payouts for the open program, GitHub hopes to regain efficiency, attract impactful research, and ensure reviewers focus on serious, well-documented issues. The four-strike rule for new researchers (based on a HackerOne "signal" requirement) further discourages spammy participation and encourages a proven track record.
What are the trade-offs for security researchers?
Compared to the old system, researchers in the public program will often earn less for similar findings, especially for high and critical vulnerabilities. The predictability of fixed rewards helps in planning but diminishes the potential upside for exceptional reports. For experienced and reputable researchers, gaining VIP status is now more valuable than ever—exclusive access brings significantly higher returns. However, it leaves newcomers and those with less established profiles at a disadvantage until they can demonstrate sustained quality contributions. By comparison, open bounty programs at other companies might still offer flexible payouts, but could soon face similar restructuring if AI-generated reports continue to flood the landscape.
Key takeaway: What does this mean for security pros and organizations?
Bounty hunters need to focus on producing high-impact, clearly documented findings and building a positive reputation if they want access to the most lucrative rewards. Organizations and project maintainers should expect a more manageable and higher-quality inflow of vulnerability reports, but may see fewer extraordinary outlier discoveries submitted to public tiers. As AI tools spread, expect other bug bounty programs to adopt stricter participation and payout controls to protect the integrity and value of their security ecosystems.
