GitHub used its Cybersecurity Awareness Month spotlight to interview @vaib25vicky, a researcher in the invite-only VIP tier of its bug bounty program. The discussion covers how they pick targets, where AI fits into their workflow, and what they tell new hunters.

Background and program context

GitHub's bounty program has run for more than a decade. This year the program was restructured around a change in incentives: submissions are rewarded for quality rather than volume, and researchers who consistently deliver high-impact work can be invited to a permanent VIP program. VIP membership brings significantly higher payouts—up to $30,000 or more for critical findings—faster response times, and early previews of beta products and features.

Entry to the VIP program is tied to resolved findings. A researcher may earn an invitation with one critical, two high, four medium, or seven low-severity resolution. The public bounty site carries the full qualification criteria. GitHub frames the emphasis on sustained, nuanced work as a response to both traditional attack surfaces and newer AI-powered ones, such as Copilot and the Copilot coding agent.

Choosing a target

@vaib25vicky came to security through coding in college, then discovered bug bounty by accident. Having used GitHub extensively in their own work, the program was a natural starting point. They stayed because of the high rewards, the difficulty, and the team—so they now focus on GitHub more than other programs.

They don't hunt by bug class. Instead, the approach starts with a feature: use it, understand how it works, and consider how it could be misused to cause a security problem. Bug classes follow from the feature rather than guiding the search.

Target selection favors areas that look complex and hard to understand. Experience lets them judge quickly whether a feature is worth the time. They spend a while on it to see whether anything interesting emerges, and if nothing does, they move to the next candidate. Once something is worth digging into, they keep using and exploring the feature until something odd happens, testing for different bug types along the way, depending on the feature.

AI as an assistant, not an autopilot

They do use AI, and describe it as a productivity gain that saves time—"a great assistant." Its limitation is that it still requires steering: "AI is like a really fast car, but it still needs a good driver."

On responsible use in bug bounty, the guidance is short: always verify what the AI gives you, and never submit a finding you haven't confirmed yourself.

AI-powered features do demand somewhat different thinking, but they don't change the fundamentals. In their view, most bugs, including high-impact ones, remain authorization issues, weak guardrails, or overlooked capabilities, all findable with the same mindset applied to traditional web bugs.

Keeping current

Their information diet mixes individual researchers and company blogs. On X they follow researchers who publish real findings and write-ups; among blogs they read company research posts and bug bounty write-ups, and they check Hacker News and security subreddits occasionally. Favorite sources include Google Project Zero, GitHub Security Lab, PortSwigger, and Hacker News.

Advice to newcomers

One thing they wish they had known at the start: progress takes time. Spending a long stretch on a target before finding anything is normal, and patience is part of the job.

Outside of research they play games and travel, taking a good trip to relax. They can be found on X, mostly, at @vaib25vicky.

Each submission to our bug bounty program is a chance to make GitHub, our products, and our customers more secure, and we continue to welcome and appreciate collaboration with the security research community.

Findings can be reported through HackerOne.