GitHub is drastically revamping its bug bounty program, leaving many security researchers and bug hunters reeling. As of July 27, 2026, the popular code-sharing platform will slash public bug bounty payouts by at least half for all severity levels. This means that even critical vulnerabilities, which have historically been worth $20,000 to $30,000 or more, will now be capped at a flat rate of $10,000.
The move is part of a broader shift towards a tiered system, where only the most skilled and experienced researchers are eligible for the highest rewards. GitHub’s VIP (Very Important Program) tier, which has been invite-only since its inception, will continue to offer payouts of $30,000 or more for high-quality submissions. However, these top-tier rewards will now be reserved exclusively for a select group of elite security researchers who have demonstrated exceptional skills and commitment to the program.
So what does this mean for the average bug hunter? For those who rely on GitHub’s public bug bounty program as their primary source of income, the reduced payouts may be a significant blow. Many had grown accustomed to earning top dollar for discovering critical vulnerabilities in popular open-source projects. With the new payout structure, even the most skilled researchers will need to significantly increase their submission volume or focus on higher-paying programs if they hope to match their previous earnings.
The move has sparked debate among security researchers and bug hunters about the future of responsible disclosure and the role of bug bounties in maintaining software security. While some argue that GitHub’s changes are necessary to maintain program integrity, others see it as a cynical attempt to cut costs at the expense of dedicated contributors who have helped make the platform more secure.
As the cybersecurity landscape continues to evolve, one thing is clear: only the most skilled and persistent researchers will thrive in this new environment. For those looking to stay ahead of the curve, now may be the time to diversify their bug bounty portfolios or explore alternative ways of earning a living as a security researcher.
In practical terms, if you’re a security researcher or bug hunter relying on GitHub’s public bug bounty program for income, it’s essential to reassess your strategy and consider diversifying your submission targets. This may involve exploring other high-paying programs or focusing on more lucrative types of vulnerabilities. Whether the changes will ultimately benefit or harm the community remains to be seen – but one thing is certain: only those who adapt quickly will remain competitive in this rapidly changing landscape.
Source: The Hacker News — 2026-07-22