Next chapter: Restructuring GitHub’s bug bounty program

July 22, 2026

GitHub is restructuring its HackerOne bug bounty program to reduce noise, prioritize high-quality research, and formalize a permanent invite-only VIP tier. Changes apply to reports filed on or after July 27, 2026; the backlog is grandfathered under prior payout terms.

Permanent VIP program

VIP researchers get higher payouts, faster responses, and closer access to GitHub security engineering.

VIP payouts:

  • Low: $1,000
  • Medium: $7,500
  • High: $20,000
  • Critical: $30,000+

Qualification (at least one of): one critical; two high; four medium; or seven low findings. Full criteria to be published on the public HackerOne page. Message: “you don’t earn more by submitting more. You earn more by submitting better.”

Restructured public bounty table (fixed rates)

  • Low: $250
  • Medium: $2,000
  • High: $5,000
  • Critical: $10,000

Static payouts replace ranges; discretionary bonuses remain possible for exceptional work. Public program remains a feeder into VIP.

Signal requirement

A HackerOne signal requirement on the public program limits submissions from researchers below the threshold (up to four initial submissions for newcomers) to reduce low-effort and AI-generated reports.

Context

GitHub cites a growing triage queue and industry-wide AI-assisted report volume. Commitment to rewarding real security research, clear communication, and conference engagement (e.g., DEF CON) remains.