Effective July 27, GitHub's top researchers will earn roughly three times more per critical finding while public tier payouts are cut roughly in half.
GitHub's bug bounty, the program that pays outside security researchers to find and report vulnerabilities in its platform, is now a two-tier labor market, effective July 27, 2026. The top tier is permanent and invite-only. The bottom tier, where most outside researchers sit, takes a roughly 50% pay cut and submits into a slower queue.
The new VIP track rewards researchers who have already shipped a track record. To qualify, a researcher needs at least one critical, two high, four medium, or seven low findings. Those researchers get direct access to GitHub's security engineering team and higher payouts per bug. GitHub's announcement frames this as a way to "focus on signal" and "reward serious researchers," with the company line: "You don't earn more by submitting more. You earn more by submitting better."
GitHub's own announcement cuts off before the new public payout table is shown in full, so the specific public numbers come from secondary reporting. The Hacker News reports the public track now pays fixed amounts at roughly half the prior range at every severity level. A critical that used to pay $20,000 to $30,000 or more now pays a flat $10,000 on the public track. A high has fallen from a $10,000 to $20,000 range to $5,000. Medium is now $2,000, down from a $4,000 to $10,000 range. Low has dropped from $617 to $2,000 to $250.
The VIP track, by contrast, pays $1,000 for low-severity findings, $7,500 for medium, $20,000 for high, and $30,000 or more for critical. The math on a critical shows the structure most clearly: $30,000 or more inside the VIP tier for a researcher who has cleared the bar, and a flat $10,000 for an outside researcher hitting the same kind of bug without the prior track record. The Hacker News discussion thread on the announcement surfaces this exact concern, with researchers flagging that the new structure caps an outside researcher's most consequential finds while the same work pays three times as much inside the tier.
GitHub's stated rationale is that the prior program rewarded volume rather than quality, and that a growing triage queue has consumed engineering time that should go to serious research. That rationale is coherent. It is also a labor-market decision about who gets paid well, who gets heard, and what kind of research GitHub wants to incentivize on the platform that hosts the bulk of the world's public code. The existing program FAQ describes a single open tier with payout ranges; the new structure replaces that with an invite-only track on top of a public track with caps. Reports already in the queue before July 27 retain the prior payout terms.
The pattern is not unique to GitHub. Across bug bounty programs, the trend has been toward gating top rewards behind reputation, invitation, or platform-specific scoring. What GitHub is doing lands harder because the platform is bigger: every private repository, every open-source maintainer, every developer who depends on GitHub Actions is downstream of how GitHub decides to pay the people who break its code on purpose. Effective July 27, the program that used to be a single open market for outside security research is now a two-track system, and the gate sits at the top.