Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level.
GitHub's payout restructure and the new VIP tier
Under changes announced by GitHub, the public HackerOne bounty schedule will move from flexible ranges to fixed payments. Public payouts will be: Low $250 (down from $617–$2,000), Medium $2,000 (down from $4,000–$10,000), High $5,000 (down from $10,000–$20,000), and Critical $10,000 (down from $20,000–$30,000+). GitHub says reports filed before July 27, including those already in its triage queue, will retain the previous payout terms.
At the same time GitHub is formalizing a permanent, invite‑only VIP tier with higher rewards: Low $1,000, Medium $7,500, High $20,000, and Critical $30,000 or more. GitHub described the changes as intended to “reduce noise while giving established researchers faster responses, higher rewards, and closer access to its security engineering team,” adding plainly, “You don't earn more by submitting more. You earn more by submitting better.”
GitHub said fixed payments should remove uncertainty and triage overhead, while reserving the right to award discretionary bonuses for exceptional work. It also stated it welcomes AI‑assisted security research and already uses AI across its internal security programs, but that researchers remain responsible “for reproducing and verifying anything their tools produce.” “The tools don't matter,” GitHub said. “The quality of the work does.”
HackerOne rules, signal thresholds, and access limits
GitHub's announcement sets explicit entry thresholds for the private VIP program: researchers can qualify by reporting at least one critical, two high, four medium, or seven low‑severity vulnerabilities. The company did not specify a time window for meeting those thresholds or whether reaching them guarantees an invitation; GitHub said fuller criteria will appear on its public HackerOne program page.
GitHub has not disclosed the HackerOne Signal threshold it will enforce; the company said researchers below that threshold will receive up to four initial submissions. Separately, HackerOne's general rules give new researchers four trial reports per program within a rolling 30‑day window — a limit that the GitHub announcement intersects with when defining who receives more than four submissions.
As of July 22, The Hacker News found that GitHub's rewards page still listed $20,000–$30,000+ for critical reports and its FAQ retained the prior VIP eligibility wording — including an older test tied to having earned at least $20,000 and submitted two reports during the preceding two years — and the FAQ reiterated that meeting those criteria did not guarantee an invitation and that GitHub reviewed candidates quarterly.
Google's Gemini 3.5 Flash Cyber and AI‑driven findings
The timing of GitHub's controls coincides with rapid improvements in AI code‑security tooling. A day before GitHub's announcement, Google introduced Gemini 3.5 Flash Cyber, a lightweight model fine‑tuned to find, validate, and patch software vulnerabilities. Google said the model will initially be available exclusively to governments and trusted partners through CodeMender as part of a limited pilot.
Google‑reported benchmark results cited by the company show Gemini 3.5 Flash Cyber finding 55 unique confirmed V8 issues, compared with 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6. Google also said its Cloud Vulnerability Research team used the model to find remote code execution flaws in public APIs and a memory‑corruption flaw in a sensitive production service within two hours, and that the model then generated what Google described as a 100%‑reliable RCE exploit that bypassed ASLR and W^X. Those benchmark figures and the production exploit result are Google‑reported and have not been independently verified.
The announcement and GitHub's statement that it already uses AI internally underline a shared trend: repeated, inexpensive model invocations let researchers and internal teams produce many candidate findings and validate more code paths without invoking larger frontier models for every attempt.
Daniel Stenberg and the curl experience with AI noise
GitHub's changes follow examples from open source projects grappling with submission volume. Curl maintainer Daniel Stenberg ended the project's cash bug bounty at the end of January 2026 after its confirmed‑vulnerability rate fell below 5% amid an increase in AI‑generated junk reports. By April, after curl had ended cash rewards and returned to HackerOne, reports were arriving at about twice the 2025 rate and 15–16% were confirmed as vulnerabilities. Stenberg said almost every report appeared AI‑assisted and most were now high quality.
Taken together — GitHub's tightened payouts and invite structure, Google's repeated‑call model, and curl's changing submission statistics — the source material describes a shift in which plausible‑looking candidate findings are increasingly abundant while reliable, product‑specific exploit chains and cross‑boundary impacts remain comparatively scarce.
What this means for researchers and open‑source maintainers
- Independent researchers: New entrants face tighter economic incentives and procedural caps. Signal thresholds and a four‑report trial window mean fewer attempts are free to learn a program's scope; the invite‑only VIP tier concentrates the highest rewards among those with established records.
- Open‑source maintainers and internal security teams: Reduced public payouts and stricter submission rules may lower volume and triage overhead, and closer private relationships could speed fixes. But projects risk narrowing the set of outside reviewers who examine complex, system‑level interactions.
GitHub's July 27 effective date will test whether fixed public payouts, higher private rewards, and signal gating reduce automated noise without excluding capable but newer researchers. The company and its counterparts are explicitly betting that clearer rewards and closer collaboration with known researchers will improve quality — even as AI tools make candidate findings more plentiful and easier to generate.
Source: The Hacker News — GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier




