GitHub Revamps Bug Bounty Program With VIP Rewards Up to $30,000
GitHub Bug Bounty changes will introduce an invite-only VIP program, new submission limits, and revised rewards. GitHub says the restructuring will help reduce AI-generated and low-effort security reports while rewarding researchers who consistently uncover meaningful vulnerabilities.
GitHub Launches Private Bug Bounty VIP Program
GitHub will make its VIP program a permanent, private initiative available only to invited security researchers.
The company designed the program for researchers who regularly submit high-quality and high-impact findings. VIP members will receive higher rewards, faster responses, and closer access to GitHub’s security engineering team.
Researchers can qualify for consideration by reporting at least one of the following:
- One critical-severity vulnerability
- Two high-severity vulnerabilities
- Four medium-severity vulnerabilities
- Seven low-severity vulnerabilities
GitHub hopes these requirements will encourage researchers to prioritize more serious security flaws instead of submitting large numbers of low-value reports.
GitHub Bug Bounty Rewards
The VIP program offers considerably higher fixed payouts than the public program.
| Vulnerability severity | VIP program reward | Public program reward |
|---|---|---|
| Low | $1,000 | $250 |
| Medium | $7,500 | $2,000 |
| High | $20,000 | $5,000 |
| Critical | $30,000 or more | $10,000 |
The rewards GitHub is phasing out currently use payout ranges rather than single fixed figures. New submissions will follow the updated reward structure once the changes take effect.
GitHub Adds HackerOne Submission Limits
GitHub is also introducing a HackerOne signal requirement for researchers participating in the public Bug Bounty program.
New researchers will initially receive four submission opportunities. The limit aims to reduce spam, AI-generated reports, and low-quality vulnerability submissions.
Researchers who build a strong reporting history can gain broader access to the public program and may eventually receive an invitation to the VIP tier.
Existing Reports Will Keep Previous Rewards
GitHub will continue evaluating reports submitted on or before July 26, 2026, under the previous bounty structure.
Reports submitted after the program changes take effect will follow the new eligibility requirements, submission restrictions, and fixed payout levels.
In other news, researchers have spotted the FakeGit campaign on GitHub. Microsoft is also retiring Copilot’s Deep Research feature, while the company has successfully resolved the recent Azure outage.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages