July 22, 2026

Bug bounty gets a velvet rope

Restructuring GitHub's bug bounty program

GitHub picks bug-hunting "VIPs" and commenters say everyone else just got snubbed

TLDR: GitHub is splitting its bug-reward program into a better-paid VIP lane and a lower, fixed-pay public lane to deal with spam and AI-written reports. Commenters are furious that the same serious problem could pay less depending on who finds it, calling the move unfair, gatekeepy, and risky.

GitHub says it is overhauling its bug bounty program — the system where outside researchers get paid for finding security flaws — because the queue is clogged with low-effort and AI-written reports. The big twist? A permanent invite-only VIP tier will now get higher payouts, faster replies, and closer access to GitHub’s security team, while the public program moves to lower, fixed rewards and a new submission limit for people without enough platform reputation. In plain English: GitHub wants fewer reports, but better ones.

And wow, the comment section heard "fewer reports" and translated it to "cool, so outsiders get paid less for the same problem?" That was the main explosion. One user bluntly argued that if the “wrong” person finds a serious flaw, the reward is capped at a much lower amount — which, critics say, could make people think twice before reporting it at all. Another didn’t even bother with subtlety, calling the whole thing a straight-up insult to non-VIPs. The hottest backlash centered on fairness: if a real security hole is real no matter who finds it, why should status change the payout?

There was also some classic internet side-eye and brainstorming. One commenter wondered whether this will just encourage researchers to form mini-cliques that self-vet each other to farm reputation and get into the velvet-rope club. Another dropped a jaw-on-the-floor comparison to unequal treatment based on identity, which instantly cranked the drama to eleven. Even the dry little "Dupe" comment had the vibe of someone arriving just to toss a match on the discourse bonfire. GitHub says it’s cutting noise and rewarding quality; a loud chunk of the crowd says it looks a lot more like gatekeeping with a payout haircut.

Key Points

  • GitHub is restructuring its bug bounty program in response to an increasing queue and a need to prioritize higher-quality vulnerability reports.
  • The company is formalizing a permanent invite-only VIP program for researchers who consistently deliver high-quality, high-impact findings.
  • GitHub is changing its public bounty table from payout ranges to static payouts for each severity level, while keeping discretionary bonuses available.
  • A HackerOne signal requirement will be added to the public program to reduce low-effort and AI-generated reports, with up to four initial submissions allowed for researchers below the threshold.
  • Reports submitted before July 27, 2026 will be handled under the previous bounty structure, while later reports will use the new system.

Hottest takes

"the 'wrong' person finds a critical vulnerability" — dinkelberg
"this is just a 'fuck you', right?" — applfanboysbgon
"a vuln is a vuln" — fragmede
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.