GitHub Overhauls Bug Bounty Program with Two-Tier System to Combat AI Report Flood
Key Takeaways
- ▸Public bug bounty rewards slashed 50–75% across all severity levels due to AI-generated report flooding
- ▸New invite-only VIP program reserves highest payouts for researchers with proven track records
- ▸First-time researchers now limited to four submissions before eligibility review under new 'signal requirement'
Summary
GitHub is implementing a major overhaul of its bug bounty program starting July 27, introducing a two-tier system that dramatically cuts public submission payouts while reserving premium rewards for an invite-only group of proven researchers. Public bounty payouts are being slashed across the board—low-severity bugs dropping from $500–$1,000 to $250, medium from $5,000 to $2,000, high-severity from $20,000 to $5,000, and critical vulnerabilities from $30,000 to $10,000.
The VIP invite-only tier, by contrast, offers substantially higher rewards: $1,000 for low-severity, $7,500 for medium, $20,000 for high-severity, and at least $30,000 for critical vulnerabilities. Entry requires a proven track record of legitimate submissions—anywhere from one accepted critical vulnerability to seven accepted low-severity findings depending on tier.
GitHub is also implementing HackerOne's "signal requirement," limiting newcomers to four reports before they establish a history of valid findings. The company attributes these changes to the surge of low-effort and AI-generated reports flooding security teams, a trend that has made it harder to identify genuinely critical vulnerabilities amid the noise. GitHub states the restructuring aims to "reduce the noise so we can focus on the signal" while making the program more rewarding for serious, professional researchers.
- Changes reflect industry-wide challenge of AI tools democratizing but overwhelming bug bounty programs
Editorial Opinion
GitHub's two-tier approach acknowledges a real problem—AI-generated noise drowning out signal—but risks fracturing the security research community into elites and outsiders. While concentrating rewards on proven researchers may improve response efficiency, it reduces the pool of potential finders and potentially suppresses innovation from emerging talent. The question is whether fewer, higher-quality reports from VIP researchers will actually improve security outcomes or simply shift the problem elsewhere.



