By Interestana AI Editorial — AI-drafted, human-overseen. How we report
GitHub Slashes Public Bug Bounty Payouts

GitHub announced on July 27, 2026, that it will significantly reduce its public bug bounty payouts, cutting rewards by at least half across all severity levels. This change aims to streamline its bug bounty program and focus resources on its top security researchers. Under the new structure, the payout for critical findings will be a fixed $10,000, a decrease from the previous range of $20,000 to $30,000+.
Concurrently, GitHub is establishing a permanent, invite-only VIP tier for its most trusted security researchers. This exclusive group will be eligible for rewards of $30,000 or more for their findings. The company stated that reports submitted before the July 27, 2026, effective date, including those already awaiting triage, will still be compensated according to the prior payout rates. This move signals a shift in how GitHub engages with the broader security community for vulnerability discovery.
The company has not explicitly detailed the criteria for inclusion in the VIP tier, but it is understood to be based on a researcher's history of impactful contributions and the quality of their submitted reports. This tiered approach is intended to foster deeper, long-term relationships with a select group of researchers who consistently deliver high-value security insights. The changes are part of GitHub's ongoing efforts to enhance its security posture and manage its bug bounty program more effectively.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.