Starting July 27, 2026, GitHub will minimize public bug bounty payouts by a minimum of half at each severity stage. Essential findings will drop from $20,000-$30,000+ to a set $10,000, whereas its everlasting invite-only VIP tier pays $30,000 or extra.
Stories filed earlier than that date, together with these already in GitHub’s rising triage queue, will retain the earlier payout phrases.
GitHub stated the adjustments are supposed to cut back noise whereas giving established researchers quicker responses, larger rewards, and nearer entry to its safety engineering crew.
“You do not earn extra by submitting extra,” the corporate stated. “You earn extra by submitting higher.”
The general public program is transferring from versatile ranges to fastened funds:
- Low: $250, down from $617-$2,000
- Medium: $2,000, down from $4,000-$10,000
- Excessive: $5,000, down from $10,000-$20,000
- Essential: $10,000, down from $20,000-$30,000+
The Hacker Information calculated that the brand new public charges are 50% decrease for medium, excessive, and significant findings and about 59% decrease for low-severity studies when measured in opposition to the underside of GitHub’s earlier ranges.
GitHub stated fastened funds ought to take away uncertainty and triage overhead, although it might nonetheless award discretionary bonuses for distinctive work.
The VIP schedule units funds at $1,000 for low-severity findings, $7,500 for medium, $20,000 for prime, and $30,000 or extra for essential vulnerabilities.
Researchers can qualify for the non-public program by reporting a minimum of one essential, two excessive, 4 medium, or seven low-severity vulnerabilities. The announcement doesn’t specify a time window for assembly these thresholds or say whether or not qualification ensures an invite. GitHub stated fuller standards will seem on its public HackerOne program web page.
GitHub has not disclosed the HackerOne Sign threshold it’ll implement. The corporate says researchers under it’ll obtain as much as 4 preliminary submissions.
Individually, HackerOne’s basic guidelines give new researchers 4 trial studies per program inside a rolling 30-day window.
When Your Personal AI Finds the Bug First
GitHub’s report controls arrive as AI makes candidate findings cheaper to generate and code assessment cheaper to repeat. Extra researchers can produce potential findings, whereas inner groups can scan code, validate points, and feed fixes into launch and commit pipelines earlier than an exterior report arrives.
A day earlier than GitHub’s announcement, Google launched Gemini 3.5 Flash Cyber, a light-weight mannequin fine-tuned to seek out, validate, and patch software program vulnerabilities. Google stated the mannequin will initially be accessible solely to governments and trusted companions by CodeMender, its code-security agent, as a part of a restricted pilot.
Google stated the mannequin could be invoked repeatedly to look at extra code paths with out utilizing a bigger frontier mannequin for each try. The corporate positions it for frequent repository scans, time-sensitive launch evaluations, and commit-scanning pipelines.
In Google-run exams, Gemini 3.5 Flash Cyber discovered 55 distinctive confirmed V8 points, in contrast with 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6.
Google individually stated its Cloud Vulnerability Analysis crew used the mannequin to seek out distant code execution flaws in public APIs and a memory-corruption flaw in a delicate manufacturing service inside two hours. The mannequin then generated what Google described as a 100%-reliable RCE exploit that bypassed ASLR and W^X. The benchmark figures and manufacturing exploit outcome are Google-reported and haven’t been independently verified.
An inner safety crew can provide an agent repository context, a project-specific risk mannequin, and a validation setting tailor-made to the working system. Techniques resembling OpenAI’s Codex Safety can then check findings, generate working proofs of idea, and suggest fixes that account for system intent and surrounding conduct.
The work can occur throughout improvement and on each related commit, quite than ready for a scheduled evaluation or an exterior report. AI doesn’t change a penetration check, however source-code assessment, check era, and first-pass validation have gotten simpler to automate.
Human testers retain extra worth the place the work requires chaining weaknesses throughout belief boundaries, recognizing business-logic failures, modeling life like assault paths, and proving materials influence.
Curl maintainer Daniel Stenberg ended the mission’s money bug bounty on the finish of January 2026 after its confirmed-vulnerability price fell under 5% amid a rise in AI-generated junk studies.
By April, after curl had ended money rewards and returned to HackerOne, studies had been arriving at about twice the 2025 price and 15-16% had been confirmed as vulnerabilities. Stenberg stated virtually each report appeared AI-assisted and most had been now top quality.
Taken collectively, GitHub’s report controls, Google’s repeated mannequin calls, and curl’s rising submission quantity level to the identical shift. AI can flood maintainers with junk, however it might probably additionally make succesful researchers quicker and let inner groups study extra code, extra usually.
A plausible-looking candidate discovering is turning into ample. Triage, exploit proof, product context, disclosure, and remediation stay constrained. A dependable exploit, a product-specific assault chain, or a discovering that crosses a boundary the seller misunderstood stays scarce.
Sign necessities and decrease public rewards could suppress automated noise, however they will additionally make entry tougher for succesful researchers with out a longtime HackerOne historical past. For a brand new HackerOne researcher, a four-report program restrict leaves little room for errors, unfamiliarity with GitHub’s safety mannequin, or a reliable discovering that’s initially scored under expectations.
The invite-only construction additionally concentrates GitHub’s closest researcher relationships amongst individuals who have already succeeded inside this system. Which will enhance pace and report high quality. It could additionally slender the vary of individuals inspecting the platform, one of many major benefits of a public bounty program.
The restructuring follows a Could 2026 coverage change that demanded working proofs of idea, demonstrated influence, validation earlier than submission, and nearer consideration to GitHub’s scope and ineligible findings.
GitHub stated it welcomes AI-assisted safety analysis and already makes use of AI throughout its inner safety applications. Researchers stay answerable for reproducing and verifying something their instruments produce.
“The instruments do not matter,” GitHub stated. “The standard of the work does.”
As of July 22, a assessment by The Hacker Information discovered that GitHub’s rewards web page nonetheless listed $20,000-$30,000+ for essential studies, whereas its FAQ retained the earlier VIP eligibility check of a minimum of $20,000 earned and two studies submitted in the course of the previous two years. The FAQ additionally stated assembly these standards didn’t assure an invite and that GitHub reviewed candidates quarterly.










