GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs
Starting July 27, 2026, GitHub will reduce public bug bounty payments, with top prizes reserved for an exclusive group.

Key points
- GitHub will cut public bug bounty payouts by at least 50% starting July 27, 2026.
- Critical vulnerabilities, meaning serious software flaws that attackers can use to cause significant harm, will see payouts drop to $10,000.
- An invite-only VIP tier will offer higher rewards, starting at $30,000.
GitHub, a major platform where developers share and work on code together, plans to reduce the money it pays for public bug bounties. This change begins on July 27, 2026, and slashes rewards by at least half for every level of severity.
Bug bounties are payments given to researchers who find and report security flaws, which are problems in software that hackers might use to cause damage. By finding these flaws before the bad guys do, researchers can help make the software safer.
GitHub's change means that if someone finds a critical vulnerability, which is a serious issue that could let hackers cause major problems, they'll now receive a fixed amount of $10,000. Previously, they might have earned between $20,000 and $30,000 or even more.
However, GitHub isn't eliminating big payouts entirely. Instead, the highest rewards will be saved for an exclusive group of researchers in what they call a VIP tier. This group, which you can only join by invitation, will still see rewards of $30,000 or more for critical findings.
Reports submitted before July 27, 2026, will not be affected by the new payment structure. This includes any reports currently waiting in GitHub's triage queue, which is a list where the company organizes and prioritizes incoming bug reports.
First reported by The Hacker News, this shift reflects a strategic decision by GitHub to manage its security costs more effectively, while still incentivizing top-tier researchers to find and report high-impact bugs.
Why is GitHub changing its payments?
GitHub is adjusting its bug bounty program to control costs and focus its resources on the most significant security threats. By limiting the highest payouts to an invite-only group, GitHub aims to ensure that its spending on bounties is used where it can have the greatest impact: on the most dangerous vulnerabilities found by the most skilled researchers.
For ordinary users, this change means GitHub is trying to maintain software security without overspending. If you use GitHub, this should encourage confidence that the platform remains secure, while also being financially responsible.
If you are a researcher, and you're not in the VIP tier, you will need to adjust expectations for potential earnings from bug bounties on GitHub. It's also a sign that building a strong reputation in the security community could lead to more exclusive opportunities, like joining the VIP tier.



