Next chapter: Restructuring GitHub’s bug bounty program
July 22, 2026
GitHub is restructuring its HackerOne bug bounty program to reduce noise, prioritize high-quality research, and formalize a permanent invite-only VIP tier. Changes apply to reports filed on or after July 27, 2026; the backlog is grandfathered under prior payout terms.
Permanent VIP program
VIP researchers get higher payouts, faster responses, and closer access to GitHub security engineering.
VIP payouts:
- Low: $1,000
- Medium: $7,500
- High: $20,000
- Critical: $30,000+
Qualification (at least one of): one critical; two high; four medium; or seven low findings. Full criteria to be published on the public HackerOne page. Message: “you don’t earn more by submitting more. You earn more by submitting better.”
Restructured public bounty table (fixed rates)
- Low: $250
- Medium: $2,000
- High: $5,000
- Critical: $10,000
Static payouts replace ranges; discretionary bonuses remain possible for exceptional work. Public program remains a feeder into VIP.
Signal requirement
A HackerOne signal requirement on the public program limits submissions from researchers below the threshold (up to four initial submissions for newcomers) to reduce low-effort and AI-generated reports.
Context
GitHub cites a growing triage queue and industry-wide AI-assisted report volume. Commitment to rewarding real security research, clear communication, and conference engagement (e.g., DEF CON) remains.