GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026Change comes in response to rise in lower-quality, AI-generated reportsVIP researchers will earn around 3-4x more per reportGitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that's available to the wider research community, under a higher-paying invitation-only program.Product Security Engineer Catherine Cassell explained that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.GitHub complains about AI-generated bug reportsFor the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to "establish a track record" – likely another response to rising AI-generated reports, which are typically of lower value."We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report," Cassell concluded.