GitHub's restructured bug bounty program takes effect on Monday, July 27, cutting rewards for public submissions by half or more at every severity level and reserving its richest payouts for an invitation-only roster of vetted researchers. The Microsoft-owned code hosting platform announced the two-tier structure on July 24, according to SC Media, and has framed it as a rescue operation for a program buried under low-effort and AI-generated vulnerability reports, a problem now degrading bug bounty schemes across the software industry.

Under the new public schedule, critical findings that previously commanded between $20,000 and more than $30,000 now pay a flat $10,000, The Hacker News reported. High-severity reports drop to $5,000, medium-severity findings to $2,000 and low-severity issues to $250. The outlet calculated that the new public rates run roughly 50 percent below prior payouts for medium, high and critical findings, and about 59 percent below for low-severity reports. Reports filed before July 27, including those sitting in GitHub's triage backlog, retain the previous terms.

Two-Tier Market for Vulnerability Research

The cuts to the open program are offset, for a select group, by a permanent VIP tier that pays $1,000 for low-severity findings, $7,500 for medium, $20,000 for high and $30,000 or more for critical vulnerabilities, figures that match or exceed the old public ceilings. Admission is earned rather than bought. According to The Hacker News, researchers qualify by landing at least one accepted critical vulnerability, two high-severity findings, four medium-severity findings or seven low-severity reports. The Register reported that VIP members also receive faster response times and closer access to GitHub's security engineering team, benefits that many researchers value nearly as much as the checks.

Entry for newcomers tightens at the same time. The Register reported that first-time participants get up to four submission opportunities before they must establish legitimacy through the signal requirement on HackerOne, the platform that hosts GitHub's program. The mechanism is designed to filter out drive-by submitters who paste scanner output or chatbot-generated findings into report templates and hope something pays out.

Catherine Cassell, a product security engineer at GitHub, described the goal in comments carried by The Register as "reducing the noise so we can focus on the signal." The company's own announcement put the incentive shift more bluntly. "You don't earn more by submitting more. You earn more by submitting better," GitHub wrote, according to The Hacker News.

AI-Generated Reports Swamp the Triage Queue

The overhaul is the most prominent response yet from a major platform to a distortion that has been building for two years. Generative AI tools have lowered the cost of producing a plausible-sounding vulnerability report to nearly zero, while the cost of disproving one still falls on human security engineers. Computing reported that HackerOne logged a 76 percent year-over-year jump in submissions through March, even as the share of reports flagging real vulnerabilities held steady at roughly 25 percent. Three out of four submissions, in other words, consume triage time and return nothing.

Smaller open source projects hit the wall first. The curl project ended cash rewards in January 2026 after its confirmed-vulnerability rate fell below 5 percent, The Hacker News noted, and curl founder Daniel Stenberg has repeatedly complained about the burden of what Computing quoted him calling "never-ending slop." Nextcloud likewise paused its program this year, citing a surge of low-quality reports. GitHub, with a security budget those projects can only envy, held out longer, but the economics eventually pointed the same direction: paying top dollar for public submissions subsidizes the flood rather than the findings.

This report is open to every reader. Subscribers unlock the full Speedway Scene archive and keep independent, rigorous journalism on the forces that move markets and power on its feet. Get the Briefing

Economics of Disclosure, Repriced

The modern bug bounty model was built on open participation. Anyone, anywhere, could study a target, file a report and get paid on merit, and that openness produced a global pipeline of talent that companies could not have hired directly. GitHub's move signals that the open end of that pipeline has become a liability. By fixing public payouts at modest flat rates and concentrating real money in a curated tier, the company is converting what was effectively an open market into something closer to a managed supplier network.

The bet carries risk. Serious researchers allocate their hours where expected returns are highest, and a $10,000 ceiling for a critical bug in one of the world's most important software platforms compares unfavorably with rewards elsewhere, to say nothing of the gray market for exploits. GitHub's wager is that the researchers who matter will graduate into the VIP tier quickly, and that the ones deterred by the lower public rates were mostly generating noise anyway. The qualification thresholds are deliberately reachable: a single accepted critical finding opens the door to the higher schedule.

There is also a defensive logic for the company. Every hour a GitHub security engineer spends debunking a fabricated report is an hour not spent on real exposure in a platform that hosts the source code, build pipelines and secrets of millions of organizations. Concentrating attention on a proven cohort is a way of buying that time back, even at the price of a less egalitarian program.

Test Case the Rest of the Industry Will Watch

Because of GitHub's scale and its position inside Microsoft, the GitHub bug bounty restructuring will function as a live experiment for every large program wrestling with the same arithmetic. The platforms themselves are already adapting: Computing reported that HackerOne has introduced agentic validation capabilities to machine-check incoming findings, while Bugcrowd has updated submission policies and detection systems to deprioritize speculative automated spam. Those tools attack the noise at intake. GitHub's redesign attacks it at the incentive layer, which is harder to game and harder to reverse.

SC Media characterized the VIP schedule as roughly three to four times the public rates, a spread wide enough to change researcher behavior if the tier delivers on its promised responsiveness. The open questions are empirical. Will valid submission rates rise once volume-based earnings disappear? Will independent researchers accept a system where the best payouts require a track record on a single platform? And will the projects that depend on outside eyes, from curl to the long tail of open source, find any equivalent mechanism, given that most cannot afford a VIP tier at all?

The answers will take quarters, not weeks, to emerge. What is already clear is that the era of uniformly open, top-dollar crowdsourced security is closing. The GitHub bug bounty program was one of the most generous public schemes in the industry when rewards only had to outbid apathy. As of Monday, it is structured for a different adversary: infinite, automated plausibility, produced at no cost by the same category of tools the industry itself built.