A record year for GitHub’s bounty program

GitHub’s Security Bug Bounty Program closed out its ninth year with its strongest performance to date, paying out more than $1.5 million across 364 vulnerabilities between February 2022 and February 2023. Total rewards distributed through HackerOne since the program’s 2016 inception now exceed $3.8 million.

The past year saw 2,042 submissions across public and private programs. June 2022 set a program record with 294 submissions, driven largely by the two-week H1-512 live hacking event held in Austin, Texas. The program also expanded community participation, growing its contributor base by 21% and seeing a 58% increase in first-time reports.

Beyond direct payouts, researchers directed over $18,000 in bounties to charitable causes, which GitHub matched, bringing total donations to $37,234.

H1-512 live hacking event

From June 6-17, 2022, GitHub partnered with HackerOne to host H1-512, a live hacking event drawing 45 in-person and remote researchers from 19 countries. Participants focused on GitHub Copilot, Codespaces, and the revamped code search tool. During the event, bounty rewards were increased across all targets, with added bonuses for high-impact findings.

Researchers filed 182 reports during the event, 94 (52%) of which were valid. Total awards reached $696,000, including $137,975 that researchers chose to donate to nonprofits—an amount GitHub matched. Alex Chapman (@ajxchapman) was named Most Valuable Hacker for his findings during the event.

Expanding non-monetary rewards

Community feedback consistently pointed to one request: more swag. In response, GitHub launched a dedicated bug bounty swag store earlier this year, making every submission eligible for a swag bonus in addition to any monetary reward. The store offers branded items that give researchers a more tangible way to showcase their participation in the program.

A black shoulder bag that is branded with the GitHub bug bounty logo. A black zip sweatshirt that is branded with the GitHub bug bounty logo. A plushie of the GitHub mascot, Mona

Disclosure and recognition efforts

This year, GitHub introduced limited disclosure for reports tied to CVEs in GitHub Enterprise Server and open source projects, allowing researchers to share their findings more broadly through the HackerOne platform. The program expects to expand the scope of disclosed reports over time.

For Cybersecurity Awareness Month in October 2022, GitHub revived its researcher spotlight series, interviewing @ahacker1—an active program participant with numerous valid findings—about their approach to hunting and their journey in the bounty community.

Looking ahead

As the program approaches its tenth anniversary, GitHub says it plans to continue refining the program with an emphasis on transparency in communications and rewards, growth of both public and private engagement, and a stronger team presence in the security research community. Researchers interested in participating can review the program’s scope, rules, and reward structure at bounty.github.com.