Categories: Web and IT News

GitHub Slashes Bug Bounty Payouts to Combat AI Report Flood

GitHub has shaken up its long-running bug bounty program. The changes come as the Microsoft-owned platform grapples with a surge in low-quality submissions. Many appear generated by artificial intelligence tools. The overhaul splits the program into two tiers. Public reports face sharp cuts in rewards. A select group of proven researchers gains access to an invite-only VIP track with far higher payouts.

The adjustments take effect July 27, 2026. Any report filed before that date follows the old rules. GitHub’s own announcement frames the moves as a way to cut through noise and reward serious work. Previous tweaks in May 2026 had already demanded working proofs of concept, clear impact demonstrations and validation of scanner or AI-assisted findings. Those steps proved insufficient.

Public payouts now sit at fixed amounts. A low-severity issue brings $250. Medium earns $2,000. High severity pays $5,000. Critical vulnerabilities command $10,000. That represents at least a 50 percent drop at every level from prior ranges. Critical findings once reached as high as $30,000 or more. The new structure removes uncertainty. Researchers know exactly what to expect. GitHub keeps room for discretionary bonuses on standout submissions.

The VIP program tells a different story. Low severity pays $1,000. Medium jumps to $7,500. High severity offers $20,000. Critical bugs start at $30,000 and can climb higher. These researchers also receive faster triage, direct lines to GitHub’s security engineers and a tighter collaborative relationship. Entry requires consistent high-quality output. One accepted critical report qualifies someone. So do two high-severity finds, four medium or seven low. The emphasis falls on quality, not volume.

“These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in,” the GitHub team wrote in the blog post. Product Security Engineer Catherine Cassell echoed the sentiment in coverage by The Register. The goal remains clear. Keep the program sustainable while honoring researchers who invest real effort.

New restrictions target unproven submitters. GitHub now applies HackerOne’s signal requirement to the public program. Those below the threshold receive only a handful of submission slots. The limit sits at four reports. Enough for a newcomer with a legitimate discovery to prove their worth. But not enough to flood the queue with speculative noise. The platform insists it wants to stay open. It simply cannot absorb endless low-effort filings anymore.

This pressure traces directly to artificial intelligence. Tools that once assisted skilled hunters now let almost anyone generate plausible-looking vulnerability reports at scale. Many lack working exploits. Others ignore scope or misstate impact. The result buries security teams under triage work. GitHub saw its queue grow despite earlier policy tightening. The Hacker News noted the May 2026 rules had already required validation before submission and closer attention to ineligible findings. Still the volume climbed.

GitHub stands far from alone. The curl project killed its cash bounty program in January 2026. Maintainer Daniel Stenberg cited a confirmed-vulnerability rate that fell below 5 percent amid a wave of AI-generated junk. “AI slop” became the term of art for these low-value submissions. They sound technical yet deliver little. Similar pauses hit other open-source initiatives and even HackerOne’s Internet Bug Bounty earlier in the year. Industry chatter on X, formerly Twitter, reflects frustration. Posts from researchers and maintainers describe overflowing inboxes and diminishing returns.

Some observers question whether the new structure truly solves the problem. Critics on Hacker News threads argue it penalizes newcomers while AI tools grow more sophisticated. A well-crafted prompt can now produce higher-signal reports. The four-submission runway may still allow determined spammers to test the waters. Yet GitHub bets that faster responses for VIPs and clear incentives will draw the best talent into deeper, more productive relationships.

The shift also highlights a broader tension. Bug bounties once democratized security research. Anyone with skill and time could participate and earn. Now platforms must filter aggressively. Static payouts simplify expectations on both sides. They reduce negotiation overhead for GitHub’s team. They set firmer boundaries for hunters. Discretionary bonuses preserve some flexibility for exceptional work that goes beyond the chart.

Earlier coverage captured the mounting strain. TechRadar reported on the initial announcement and noted the 3-to-4 times payout multiplier for VIP researchers. The article highlighted how the changes formalize what had been an informal tier for top contributors. GitHub had already been steering its strongest partners into closer collaboration. Making the VIP track permanent and public simply codifies that reality.

Response times matter as much as money. Security teams drown in reports. Valid issues sit unaddressed while staff chase ghosts. Faster triage for proven researchers creates a virtuous cycle. High-quality submissions receive quick validation and fixes. That encourages more of the same. Newcomers still have a path in. Four submissions provide runway. Strong performance builds signal. The door to VIP status swings open for those who clear the bar.

GitHub plans additional investments. Faster overall response times. Clearer explanations of severity decisions. More direct engagement at conferences such as DEF CON. The bounty table forms one piece of a larger effort to rebuild trust and focus. The security research community remains one of the platform’s greatest assets, the company stressed. These adjustments aim to honor that contribution rather than dilute it.

Industry watchers expect other organizations to study the model closely. Payout compression for the public tier combined with premium access for elites could spread. The AI genie refuses to return to its bottle. Tools improve daily. What once required deep expertise now emerges from careful prompting. Bug bounty operators must adapt or risk collapse under the weight of generated content.

Grandfathering existing reports softens the transition. Researchers who filed before the cutoff avoid surprise. Yet from July 27 onward the new economics apply. The message lands unmistakably. Volume alone no longer pays. Depth, validation and proven track record drive rewards. GitHub has drawn a line. The rest of the sector may soon follow.

GitHub Slashes Bug Bounty Payouts to Combat AI Report Flood first appeared on Web and IT News.

awnewsor

Recent Posts

Rivian Takes On the U.S. Government to Reclaim Tens of Millions in Unconstitutional Tariffs

Rivian is fighting back. The electric vehicle maker filed suit against the U.S. government Thursday…

3 hours ago

The Code That Watches Itself: Building Debuggers From Scratch

Tim Misiak once worked on Microsoft’s debugger platform. Twice he left the team. Each departure…

3 hours ago

OpenAI’s Rogue AI Models Breached Hugging Face in a Real-World Cyberattack

Science fiction became fact last week when OpenAI acknowledged that two of its advanced AI…

3 hours ago

Netflix and Prime Video Bet on AI Homepages as Viewers Push Back Hard

Streaming giants Netflix and Prime Video stand on the brink of a major shift. Both…

3 hours ago

European Banks Race to Harness AI for Risk and Compliance Amid ECB Deadlines

European banks have stepped up spending on artificial intelligence tools aimed at risk management and…

3 hours ago

Apple’s $250 Million Siri Settlement Wins Court Nod, Paving Way for Payouts to Millions of iPhone Buyers

A federal judge has given preliminary approval to Apple’s $250 million settlement in a class-action…

3 hours ago

This website uses cookies.