GitHub Cuts Public Bug Bounties as AI Reports Surge
For more than a decade, GitHub’s bug bounty program has paid security researchers to identify flaws before attackers can exploit them. The model has become harder to manage as AI tools lower the cost of producing plausible vulnerability reports. GitHub said a growing queue of low-effort and AI-generated submissions was consuming review capacity, prompting the Microsoft-owned platform to favor researchers with a proven record and findings that deliver greater security impact.
GitHub said on July 22, 2026, that a new structure will apply to reports submitted from July 27. Public awards will be fixed at $250 for low-severity flaws, $2,000 for medium, $5,000 for high and $10,000 for critical issues, at least halving payouts from prior ranges. An invite-only VIP program will pay $1,000, $7,500, $20,000 and at least $30,000, respectively. The public program will also impose a HackerOne signal threshold; researchers below it can make up to four initial submissions while establishing a track record.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.