Cyber Resilience
← All news
Corroborated

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Our takeGitHub is halving public bug bounty payouts from July 27 and shifting the top rewards to its invite-only VIP tier. The move matches the broader repricing driven by the surge in AI-assisted reports.
Sources (2)
What this means for you — Security leader:GitHub is halving public bug bounty payouts from July 27 (critical drops from $20k–$30k+ to $10k fixed) while moving top rewards to an invite-only VIP tier paying $30k+. Pre-July 27 reports keep old rates.
What this means for you — Lean IT orgs:This change only affects you if you hunt bugs for GitHub bounties. Most teams can ignore it; continue reporting any GitHub security issues through normal channels.
What this means for you — MSP:Advise clients who participate in public bug bounties that GitHub payouts are being cut in half from July 27; only pre-cut reports and the new VIP tier keep higher rewards.
What this means for you — Researcher:Submit any pending GitHub reports before July 27 to lock in the old payout schedule; after that, critical public bounties are capped at $10k and top rewards require VIP invitation.