• 2 min read
GitHub restructures its bug bounty program
GitHub is launching a permanent VIP bug bounty tier, cutting public payouts, and limiting submissions to reduce low-effort and AI-generated reports.

Image: Hacker News
GitHub is overhauling its bug bounty program to prioritize high-quality, high-impact research over report volume. The changes, announced July 22, 2026, follow months of analysis and feedback about a growing submission queue and researcher experience.
GitHub’s permanent VIP bug bounty program
GitHub is formalizing a permanent private, invite-only VIP program for researchers who consistently produce strong findings. Qualified participants will receive:
- Higher payouts
- Faster response times
- A closer working relationship with GitHub’s security engineering team
The VIP bounty table is:
- Low: $1,000
- Medium: $7,500
- High: $20,000
- Critical: $30,000+
GitHub says it will publish qualification criteria on its public HackerOne page. Researchers must demonstrate consistent quality by achieving at least one of the following: one critical finding, two high findings, four medium findings, or seven low findings.

Recommended reading
Windows 10 PCs face three times the security risk
The company’s stated goal is to reward better research rather than more submissions. As GitHub puts it, “you don’t earn more by submitting more. You earn more by submitting better.”
New public bounty rates and submission limits
GitHub is also replacing its public bounty ranges with fixed payouts, which it says will reduce uncertainty for researchers and administrative overhead for its team. The new public rates are:
- Low: $250
- Medium: $2,000
- High: $5,000
- Critical: $10,000
The public program will remain open to the broader security community and act as a potential path into the VIP program. GitHub will retain the ability to award discretionary bonuses for exceptional work.
To reduce low-effort and AI-generated reports, the public program will introduce a HackerOne signal requirement. Researchers who have not met the threshold will have a limited number of submissions while building a track record. HackerOne allows those researchers up to four initial submissions.
Reports submitted before the changes take effect will be handled under the previous bounty structure. The new system applies to reports submitted on or after July 27, 2026.
GitHub also says it is working on faster response times, clearer severity decisions, and more community engagement, including direct contact with researchers at conferences such as DEFCON.
Written by
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via Hacker News


