BotBeat
...
← Back

> ▌

GitHubGitHub
UPDATEGitHub2026-07-23

GitHub Overhauls Bug Bounty Program with Two-Tier System to Combat AI Report Flood

Key Takeaways

  • ▸Public bug bounty rewards slashed 50–75% across all severity levels due to AI-generated report flooding
  • ▸New invite-only VIP program reserves highest payouts for researchers with proven track records
  • ▸First-time researchers now limited to four submissions before eligibility review under new 'signal requirement'
Source:
Hacker Newshttps://www.theregister.com/devops/2026/07/23/github-slashes-public-bug-bounty-payouts-as-ai-report-flood-buries-its-security-team/5277046↗

Summary

GitHub is implementing a major overhaul of its bug bounty program starting July 27, introducing a two-tier system that dramatically cuts public submission payouts while reserving premium rewards for an invite-only group of proven researchers. Public bounty payouts are being slashed across the board—low-severity bugs dropping from $500–$1,000 to $250, medium from $5,000 to $2,000, high-severity from $20,000 to $5,000, and critical vulnerabilities from $30,000 to $10,000.

The VIP invite-only tier, by contrast, offers substantially higher rewards: $1,000 for low-severity, $7,500 for medium, $20,000 for high-severity, and at least $30,000 for critical vulnerabilities. Entry requires a proven track record of legitimate submissions—anywhere from one accepted critical vulnerability to seven accepted low-severity findings depending on tier.

GitHub is also implementing HackerOne's "signal requirement," limiting newcomers to four reports before they establish a history of valid findings. The company attributes these changes to the surge of low-effort and AI-generated reports flooding security teams, a trend that has made it harder to identify genuinely critical vulnerabilities amid the noise. GitHub states the restructuring aims to "reduce the noise so we can focus on the signal" while making the program more rewarding for serious, professional researchers.

  • Changes reflect industry-wide challenge of AI tools democratizing but overwhelming bug bounty programs

Editorial Opinion

GitHub's two-tier approach acknowledges a real problem—AI-generated noise drowning out signal—but risks fracturing the security research community into elites and outsiders. While concentrating rewards on proven researchers may improve response efficiency, it reduces the pool of potential finders and potentially suppresses innovation from emerging talent. The question is whether fewer, higher-quality reports from VIP researchers will actually improve security outcomes or simply shift the problem elsewhere.

Generative AIAI AgentsCybersecurityMarket Trends

More from GitHub

GitHubGitHub
PRODUCT LAUNCH

GitHub Code Quality Launches Generally Available with AI-Assisted Detection and Autofix

2026-07-20
GitHubGitHub
UPDATE

GitHub Brings AI-Powered Security Detection to Pull Requests

2026-07-16
GitHubGitHub
INDUSTRY REPORT

87% of AI-Generated Code Projects Have Security Issues, Report Finds Massive Quality Gaps

2026-07-14

Comments

Suggested

AnthropicAnthropic
PRODUCT LAUNCH

DingDuff: Claude-Powered Legal Research Tool Launches with Tip-Jar Model

2026-07-23
AmazonAmazon
INDUSTRY REPORT

Big Tech's $1.65 Trillion AI Infrastructure Bet: Understanding the Commitments vs. Debt

2026-07-23
Google / AlphabetGoogle / Alphabet
RESEARCH

Research Shows Stronger AI Agents Cause More Harm Than Weaker Models

2026-07-23
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us