GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
20:37 · July 22, 2026 · Hacker News AI Section

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub's growing triage queue, will retain the previous payout terms. GitHub said the
Summary
GitHub will halve its public bug bounty payouts starting July 27, 2026, moving critical reports from a previous range of $20,000–$30,000+ to a fixed $10,000 while shifting higher rewards to a permanent invite-only VIP tier that begins at $30,000 for critical findings. Low-, medium-, and high-severity public reports will also receive fixed payments that are roughly 50 percent lower than the prior ranges, with the company stating that fixed amounts reduce triage overhead and uncertainty. Reports already in the queue or submitted before the cutoff retain the old terms.
The changes aim to reduce noise from low-quality submissions and concentrate resources on researchers who demonstrate verified impact. Qualification for the VIP tier requires a minimum number of accepted reports at each severity level, after which invitees gain faster responses and direct access to GitHub’s security engineering team. The company has not published the exact HackerOne Signal threshold or time window for qualification.
These adjustments coincide with wider use of AI tools that lower the cost of generating candidate vulnerabilities. Google’s Gemini 3.5 Flash Cyber model, released the day before GitHub’s announcement, is designed for repeated scans of code paths and can produce working exploits in hours; internal tests showed it identifying more confirmed V8 issues than earlier models. Similar automation has already affected other projects: the curl maintainer ended cash rewards in January 2026 after the confirmed-vulnerability rate dropped below 5 percent amid rising AI-generated reports, though quality later improved once cash incentives were removed.
The result is a clearer separation between first-pass discovery, which AI can now perform at scale, and the remaining scarce skills of chaining findings across trust boundaries, proving material impact, and validating product-specific attack paths. GitHub continues to accept AI-assisted research provided researchers reproduce and verify the results themselves.
Why it matters
This article is highly relevant for security professionals as it highlights how AI is fundamentally altering the economics and operations of vulnerability management and bug bounties. Dutch enterprises running bug bounty programs or utilizing AI for code security must adapt to these shifts to effectively manage AI-generated reports and leverage new AI security models.








