GitHub Slashes Bug Bounty Payouts Amid AI Report Flood
GitHub is overhauling its bug bounty program from July 27, cutting public rewards significantly and introducing an invite-only tier for proven researchers. Critical vulnerability payouts drop from $30,000 to $10,000 for public submissions, while invited elite researchers can still earn $30,000 or more.
The Microsoft-owned platform blames a surge of low-effort, AI-generated reports for burying its security team. New researchers will face submission caps until they establish credibility, and invitations to the premium tier require a track record of accepted vulnerability reports.
