2 min read

GitHub cuts public bug bounty payouts

GitHub will cut public bug bounty payouts on July 27 while offering larger rewards to proven researchers in a new invite-only program.

Image: The Register

GitHub will overhaul its bug bounty program on July 27, cutting payouts for public submissions while reserving its largest rewards for an invite-only group of proven security researchers.

The Microsoft-owned code-hosting platform says the changes respond to a growing volume of low-effort and AI-generated reports. The new structure is intended to reduce noise and direct more money toward researchers who consistently uncover valid vulnerabilities.

“These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.”

Cathering Cassell, product security engineer at GitHub

GitHub’s new bug bounty payouts

For researchers remaining in the public program, rewards will change substantially:

Recommended reading

GitHub restructures its bug bounty program

  • Low severity: $250, down from $500–$1,000
  • Medium severity: up to $2,000, down from $5,000
  • High severity: up to $5,000, down from $20,000
  • Critical severity: up to $10,000, down from $30,000

GitHub’s new invite-only VIP program will offer higher rewards: $1,000 for low-severity findings, $7,500 for medium bugs, $20,000 for high-severity issues, and at least $30,000 for critical vulnerabilities.

Entry will depend on a proven record of valid reports. Researchers may qualify with anything from one accepted critical vulnerability to seven accepted low-severity findings.

Limits for new researchers

GitHub is also enabling HackerOne’s “signal requirement,” which limits the number of reports newcomers can submit until they establish a history of legitimate findings. Genuine newcomers will still have up to four opportunities to demonstrate their value.

Reports already in GitHub’s backlog will continue to be evaluated under the previous payout structure. The changes follow tighter report-quality requirements introduced earlier this year, including warnings against flooding the platform with AI-assisted submissions.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via The Register

/ Keep reading