GitHub restructures bug bounty around quality over quantity
GitHub is overhauling its bug bounty program in an effort to cut down on report noise and reward deeper, more consistent security research. The changes include a formal private program for top researchers, static payouts in the public program, and new signal requirements to filter out low-effort submissions.
The restructuring comes as the program faces a growing queue of reports. GitHub says the goal is twofold: reduce noise so the team can focus on actual vulnerabilities, and make the program more rewarding for serious researchers.
New permanent VIP program for proven researchers
GitHub is formalizing an invite-only VIP program for researchers who consistently deliver high-quality work. VIP participants receive higher payouts, faster response times, and direct access to GitHub's security engineering team. The program is designed to give researchers who invest heavily in understanding GitHub a working relationship that reflects that effort.
VIP program bounty table:
| Severity | Payout |
|---|---|
| Low | $1,000 |
| Medium | $7,500 |
| High | $20,000 |
| Critical | $30,000+ |
To qualify, researchers must demonstrate consistent quality through at least one of the following on the public program: one critical finding, two high findings, four medium findings, or seven low findings. GitHub says the incentive structure is shifting away from sheer submission volume.
- One critical finding
- Two high findings
- Four medium findings
- Seven low findings
"You don't earn more by submitting more," GitHub notes. "You earn more by submitting better."
Public program moves to static payouts
The public bounty table is being adjusted to better align with the new emphasis on quality, and payouts are moving to fixed amounts per severity level instead of ranges. GitHub says ranges create uncertainty for researchers and administrative overhead for the team. Static payouts make expectations clear on both sides, while GitHub retains the option to award discretionary bonuses for exceptional work.
New public program bounty table:
| Severity | Payout |
|---|---|
| Low | $250 |
| Medium | $2,000 |
| High | $5,000 |
| Critical | $10,000 |
The lower public rates are intended to free up resources for more tailored attention and higher rewards within the VIP program, while keeping the public program open as an entry point and feeder into the VIP tier.
Signal requirements target report noise
To curb the volume of low-effort and AI-generated reports, GitHub is enforcing a HackerOne signal requirement on the public program. Researchers who haven't yet met the signal threshold will be limited in how many submissions they can make while establishing a track record.
The threshold is not intended to block new researchers. HackerOne allows up to four initial submissions for those who don't meet the requirement, which GitHub says is enough runway for a newcomer with a legitimate finding to demonstrate capability.
Backlog honored under old structure
Reports submitted before the changes take effect will be paid under the previous bounty structure. Only reports submitted on or after July 27, 2026 will be assessed under the new table and rules.
GitHub also reaffirms that its broader commitments remain unchanged: prompt payouts, clear communication, and treating researchers as partners. The company says future efforts will focus on faster response times, clearer severity reasoning, and more community engagement, including presence at security conferences like DEFCON.



