GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, down from previous ranges. The changes aim to reduce noise and prioritize faster responses for established researchers, but may also make it harder for new or less experienced researchers to earn rewards. Google is also introducing AI-powered tools to automate vulnerability detection and patching, though the company emphasizes that human expertise remains crucial for validating findings and creating effective exploits.
GitHub is implementing a major overhaul of its public bug bounty program, effective July 27, 2026. The company will cut public bug bounty payouts by at least half at every severity level, with critical findings dropping from $20,000-$30,000+ to a fixed $10,000. The top rewards will now be exclusively available through a private, invite-only VIP tier, paying $30,000 or more.
Reports filed before the change date will retain the previous payout terms. GitHub stated that these changes are intended to reduce noise while giving established researchers faster responses, higher rewards, and closer access to its security engineering team, emphasizing that "you earn more by submitting better." The program is moving from flexible ranges to fixed payments, with the following new rates: Low: $250, down from $617-$2,000; Medium: $2,000, down from $4,000-$10,000; High: $5,000, down from $10,000-$20,000; and Critical: $10,000, down from $20,000-$30,000+.
Google is also introducing Gemini 3.5 Flash Cyber, a lightweight AI model designed to find, validate, and patch software vulnerabilities. The model will initially be available exclusively to governments and trusted partners through CodeMender, a pilot program. Google claims the model can find 55 unique V8 issues, compared with 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6, and it generated a 100%-reliable RCE exploit in two hours.
Separately, the curl maintainer Daniel Stenberg ended the project's cash bug bounty at the end of January 2026 after its confirmed-vulnerability rate fell below 5% amid an increase in AI-generated junk reports. Google's Cloud Vulnerability Research team used the Gemini 3.5 Flash Cyber model to find remote code execution flaws in public APIs and a memory-corruption flaw in a sensitive production service within two hours.
GitHub has announced a May 2026 policy change requiring working proofs of concept, demonstrated impact, validation before submission, and closer attention to GitHub's scope and ineligible findings. The company welcomes AI-assisted security research, but stresses that researchers remain responsible for reproducing and verifying any findings generated by their tools. As of July 22, a review by The Hacker News found that GitHub's rewards page still listed $20,000-$30,000+ for critical reports, while its FAQ retained the previous VIP eligibility test of at least $20,000 earned and two reports submitted during the preceding two years.
