The platform is cutting its public bug bounty, the program that pays outside researchers to report real vulnerabilities, and adding a VIP tier that pays more to vetted finders.
The independent security researchers who make a living reporting real flaws to GitHub got a new rate card on Wednesday. The public tier pays less at every severity level. A new private tier pays more, but only to researchers GitHub has already vetted.
A bug bounty, in plain terms, is a paid invitation. GitHub pays outside researchers, often freelancers, a set fee for each real security flaw they report, then pays more for more dangerous flaws. The model worked when submissions were scarce relative to triage capacity. It breaks when submission cost collapses.
That collapse is the AI variable. Industry coverage now documents programs across the security industry drowning in machine-generated reports, low-quality probes dressed as findings, and automated noise that consumes engineer hours before a human ever looks at it. GitHub is the first top-tier public program to publish a price for the difference. The cut is not a punishment of researchers. It is a redesign of who the program is for.
The changes, calculated by The Hacker News and picked up by The Register, were announced on July 22 and take effect July 27. The lowest public payout drops to $250, down from a $617–$2,000 range. Medium severity drops to a flat $2,000 from a $4,000–$10,000 band. High severity falls to $5,000 from $10,000–$20,000. Critical falls to $10,000 from $20,000–$30,000 and up.
A new permanent private "VIP" tier raises the floor: $1,000 for low findings, $7,500 for medium, $20,000 for high, and $30,000-plus for critical. Entry is gated by a findings history: one critical, two high, four medium, or seven low reports qualify a researcher for the upper tier. GitHub frames the shift as a queue problem. "Quality submissions take longer to surface because triage is increasingly buried in noise," the company wrote, pointing to a HackerOne Signal threshold and a four-submission cap for sub-threshold researchers as the operational lever. The post is the second half of a deliberate two-step pivot. The first half, "Raising the bar," laid out the diagnosis a few weeks earlier. Discretionary bonuses for exceptional public submissions remain on the table.
The first is income and time for the independent researcher labor pool. A medium-severity public check, the bread-and-butter payout for many freelancers, drops from a $4,000–$10,000 band to a flat $2,000. The new VIP tier, by contrast, pays $7,500 for the same work. The split means the program is now two markets: a thin public one, and a thicker private one reserved for researchers GitHub has already qualified. Newcomers and casual reporters take the lower rate by default.
The second stake is the security of every project hosted on GitHub. The platform sits underneath most modern open source, and a slower, noisier triage pipeline is a slower pipeline for the real flaws that would otherwise be reported through it. GitHub is betting that concentrating payouts on proven finders, plus HackerOne's signal filter, will buy back triage time. Whether the bet holds depends on whether the VIP tier absorbs the rejected public volume or simply relocates it.
The third stake is the one the wire story will not tell you. GitHub's two-tier rate card is the first published answer to a question every platform running an open security program is now asking: what does trust cost when findings are cheap? If the GitHub model holds, expect competing platforms to publish their own signal thresholds and their own tiered payouts within a year. The hidden unit of bug-bounty economics is shifting from "per flaw reported" to "per finding the platform believes."
The cleanest test of whether GitHub's redesign is a generic AI-era response or a GitHub-specific cut is a comparison. If a comparable platform, say a major cloud provider with a parallel public program, holds its uniform public payouts and gets through the queue by tightening the Signal threshold alone, the VIP tier is an artifact of GitHub's specific researcher base, not a market-wide repricing. If the comparator follows GitHub into a split program, the cut is the new floor.
The cleanest follow-up is the VIP criteria. GitHub says full qualification mechanics will be detailed on HackerOne. Until that page is live, the program is a price tag without a contract. Researchers will want to know whether the threshold is one critical, two high, four medium, or seven low findings in a defined window, and whether the new tier renews, decays, or gets re-earned each quarter. The answer will tell them whether the upper market is durable or a one-time recognition list.
For now, the new rule of thumb is simple: in a queue where the floor is automated, the price of being believed has to go up. GitHub put a number on it.