{"slug": "github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program", "title": "GitHub Bug Bounty Cuts: AI Report Spam Forces Two-Tier Program", "summary": "GitHub cut its public bug bounty payouts by at least 50% across all severity levels effective July 27, 2026, and moved top rewards to an invite-only VIP tier, citing a flood of AI-generated spam reports. The company said the restructuring is a direct response to low-effort, unvalidated AI submissions, with HackerOne reporting a 76% jump in submissions year-over-year through March 2026 but only 25% being valid. GitHub is not alone: curl ended its bug bounty in January 2026, Google stopped accepting AI-generated reports in March 2026, and other platforms have added filters or paused programs.", "body_md": "Starting today, GitHub has cut its public bug bounty payouts by at least 50% across every severity level and moved its highest rewards into a permanent, invite-only VIP tier. The reason is not a budget squeeze. It is AI-generated spam — and GitHub is not the only program being driven to this point.\n\n## What Changed\n\nThe new public program rates, effective July 27, 2026:\n\n| Severity | Old Rate | New Rate | Cut |\n|---|---|---|---|\n| Critical | $20,000-$30,000+ | $10,000 | ~55-67% |\n| High | up to $20,000 | $5,000 | 75% |\n| Medium | up to $7,500 | $2,000 | ~73% |\n| Low | $1,000 | $250 | 75% |\n\nThe invite-only VIP tier pays what the public program used to pay: Critical $30,000+, High $20,000, Medium $7,500, Low $1,000. Reports filed before July 27 retain the previous payout terms.\n\nTo qualify for VIP, you need to have already found at least one critical issue, two high-severity issues, four medium issues, or seven low-severity issues in GitHub”’s systems. [GitHub published the full criteria on its blog](https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/). The path is built entirely around demonstrated quality.\n\n## Why This Happened\n\nGitHub”’s security team did not ask for fewer reports. It asked for fewer bad ones. HackerOne reported a 76% jump in submissions year-over-year through March 2026, but the share of reports flagging real vulnerabilities stayed flat at around 25%. Three out of four reports were noise and an increasing share of that noise was AI-generated.\n\nGitHub was explicit about the driver. The company said the restructuring is a direct response to the flood of low-effort and AI-generated reports now accompanying many bug bounty programs. It was careful to note it is not opposed to researchers using AI. It expects AI to become central to security research workflows. The problem is speculative, unvalidated output: using AI to generate reports without actually confirming findings first.\n\n## GitHub Is Not Alone\n\nThis is not a GitHub-specific problem. The AI spam crisis has been building across the industry for over a year:\n\n**curl ended its bug bounty in January 2026.** Creator Daniel Stenberg shut it down after the confirmed-vulnerability rate fell below 5%. He described it as never-ending slop. None of the AI-generated reports were actual vulnerabilities, but each took significant time to review and dismiss.[His full write-up](https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/)is worth reading.**Google stopped accepting AI-generated reports in March 2026.** Volume and noise became unmanageable.**Nextcloud paused its program entirely** amid similar pressure.**HackerOne launched AI triage filters** to screen generated submissions before they reach human reviewers, and paused the Internet Bug Bounty in April 2026.**Bugcrowd added mandatory identity verification, CAPTCHAs, and rate limiting** in March 2026 to stem the flood.\n\nGitHub”’s restructuring is the most significant response yet, because [GitHub”’s program](https://bounty.github.com/) is one of the largest and most visible in existence. If this model holds, others will follow.\n\n## The Legitimate Researcher Problem\n\nThe two-tier model makes sense as a response to spam. It also raises a real concern about access.\n\nPublic bug bounty programs have always been valuable precisely because they capture intelligence from researchers who are not already well-known. A newcomer who finds a critical vulnerability in GitHub”’s infrastructure deserves the same reward as an established researcher. Under the new structure, that newcomer gets $10,000. A VIP gets $30,000 for the same finding.\n\nThe 4-report limit for new researchers before signal score requirements kick in is a narrow window. Not a lot of room to learn GitHub”’s security model, work through the disclosure process, or have a finding mis-scored on the first attempt. Signal requirements will suppress automated noise, but they can also suppress legitimate new voices. GitHub is betting the quality gains outweigh the access costs. That is a defensible bet, but it is still a bet.\n\n## What Researchers Should Do Now\n\n**Check your HackerOne signal score.** Signal score now affects program access.**Review your finding history.** If you have previously found critical or high-severity issues in GitHub”’s systems, you may already qualify for VIP. Watch GitHub”’s HackerOne page for the formal rollout.**Validate before you submit.** AI-assisted research is fine. GitHub said so explicitly. Unvalidated AI output is not. If a tool flags something, confirm it manually before filing.\n\nThe broader issue the industry is working out in real time: AI is genuinely useful for finding security issues, but useful tools get misused at scale. The economics of public bug bounty programs were not designed to absorb a 76% submission spike with flat signal quality. Something had to give.\n\nGitHub”’s answer is a two-tier model. It is defensible. It is also the beginning of a wider conversation about how public security research gets compensated in an era when anyone with a prompt can file a vulnerability report. [The Register”’s full analysis](https://www.theregister.com/devops/2026/07/23/github-slashes-public-bug-bounty-payouts-as-ai-report-flood-buries-its-security-team/) is worth reading alongside GitHub”’s official post.", "url": "https://wpnews.pro/news/github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program", "canonical_source": "https://byteiota.com/github-bug-bounty-cuts-ai-report-spam-two-tier/", "published_at": "2026-07-27 00:14:49+00:00", "updated_at": "2026-07-27 00:31:50.464811+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-ethics", "developer-tools"], "entities": ["GitHub", "HackerOne", "curl", "Google", "Nextcloud", "Bugcrowd", "Daniel Stenberg"], "alternates": {"html": "https://wpnews.pro/news/github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program", "markdown": "https://wpnews.pro/news/github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program.md", "text": "https://wpnews.pro/news/github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program.txt", "jsonld": "https://wpnews.pro/news/github-bug-bounty-cuts-ai-report-spam-forces-two-tier-program.jsonld"}}