GitHub Overhauls Bug Bounty Program, Prioritizing Quality and Rewarding Top Researchers
GitHub is restructuring its bug bounty program to emphasize high-quality submissions and foster deeper relationships with top security researchers through a new permanent VIP program.

GitHub has announced significant changes to its bug bounty program, aiming to address an increasing queue of reports and refocus efforts on "signal over noise." The initiative seeks to reward consistent, high-impact security research, moving away from a purely volume-based incentive structure.
The core of the restructuring is the introduction of a permanent, invite-only VIP program. This program is designed for researchers who consistently deliver high-quality and high-impact work. VIP researchers will benefit from higher payouts, faster response times, and a more direct working relationship with GitHub's security engineering team. The tiered payout structure for VIPs ranges from $1,000 for low-severity findings to $30,000 or more for critical vulnerabilities, with clear qualification criteria based on the number and severity of accepted submissions.
To qualify for the VIP program, researchers must achieve specific milestones, such as submitting one critical finding, two high findings, four medium findings, or seven low findings. This approach incentivizes depth and quality over the sheer quantity of reports submitted, encouraging researchers to invest more time in understanding GitHub's complex systems.
Alongside the VIP program, GitHub is also adjusting its public bug bounty program. The payout table for public submissions has been updated with static amounts for each severity level: $250 for low, $2,000 for medium, $5,000 for high, and $10,000 for critical. These static payouts aim to provide clearer expectations for researchers and reduce administrative overhead, while still allowing for discretionary bonuses for exceptional work. This adjustment supports the VIP program by enabling more tailored attention and higher rewards for its members.
To further reduce low-effort and AI-generated reports, GitHub is implementing a "signal requirement" through its HackerOne platform. Researchers who do not yet meet this threshold will have a limited number of submissions allowed while they build a track record. GitHub emphasizes that this is not intended to block new researchers, as the platform allows up to four initial submissions, which should be sufficient for genuine findings to be demonstrated.
GitHub reaffirms its commitment to rewarding legitimate security research, promising continued prompt payouts and clear communication. Reports submitted before the changes take effect on July 27, 2026, will be honored under the previous bounty structure. The company is also investing in faster response times, clearer severity reasoning, and increased community engagement through events and outreach.
These changes reflect a broader industry trend of bug bounty programs evolving to manage increasing report volumes and to better incentivize and retain top-tier security talent. By formalizing a VIP track and refining public program incentives, GitHub aims to cultivate a more sustainable and effective security research ecosystem.