GitHub reduces public bug bounty payouts as AI-generated reports overwhelm security team
GitHub is lowering public bug bounty rewards and restricting first-time researcher access after AI-generated security reports created unsustainable volume for the security team to triage.
Payout Structure Changes and Researcher Limits
GitHub has reduced maximum payouts for its public bug bounty program and introduced new restrictions for first-time researchers. The changes respond to an influx of AI-generated security reports that the company's security team found difficult to process at scale.
The platform is reserving the highest rewards for a hand-picked group of proven security researchers. New participants face tighter submission requirements and lower initial payouts until they establish a track record of valid findings.
AI Report Volume Creates Triage Burden
The security team cited an unsustainable increase in submission volume driven by AI-generated vulnerability reports. While automation can accelerate security research, the resulting flood of reports—many of which required significant time to assess—exceeded the team's capacity to provide timely review.
AI-assisted tools enable researchers to generate reports at scale, but quality and accuracy vary. The challenge for bug bounty programs lies in distinguishing legitimate findings from false positives or duplicate submissions when volume outpaces manual review capacity.
Tiered Access Model Emerges
GitHub's restructured program creates distinct tiers based on researcher history. Established researchers with proven track records retain access to higher payouts and faster review, while newcomers must demonstrate value before receiving similar treatment.
The shift reflects a broader tension in security research as AI tools democratize access but also generate noise. Bug bounty programs must balance encouraging new talent against maintaining operational capacity to review submissions effectively.