- GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026
- Change comes in response to rise in lower-quality, AI-generated reports
- VIP researchers will earn around 3-4x more per report
GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.
Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that's available to the wider research community, under a higher-paying invitation-only program.
Product Security Engineer Catherine Cassell explained that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.
GitHub complains about AI-generated bug reports
For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.
Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.
Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.
GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to "establish a track record" – likely another response to rising AI-generated reports, which are typically of lower value.
"We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report," Cassell concluded.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.









English (US) ·