GitHub reduces public bug bounty payouts as AI-generated reports overwhelm security team

GitHub is lowering public bug bounty rewards and restricting first-time researcher access after AI-generated security reports created unsustainable volume for the security team to triage.

Abstract visualization of high-volume report triage in bug bounty programs
AI-generated illustration · Sylvaris

Payout Structure Changes and Researcher Limits

GitHub has reduced maximum payouts for its public bug bounty program and introduced new restrictions for first-time researchers. The changes respond to an influx of AI-generated security reports that the company's security team found difficult to process at scale.

The platform is reserving the highest rewards for a hand-picked group of proven security researchers. New participants face tighter submission requirements and lower initial payouts until they establish a track record of valid findings.

AI Report Volume Creates Triage Burden

The security team cited an unsustainable increase in submission volume driven by AI-generated vulnerability reports. While automation can accelerate security research, the resulting flood of reports—many of which required significant time to assess—exceeded the team's capacity to provide timely review.

AI-assisted tools enable researchers to generate reports at scale, but quality and accuracy vary. The challenge for bug bounty programs lies in distinguishing legitimate findings from false positives or duplicate submissions when volume outpaces manual review capacity.

Tiered Access Model Emerges

GitHub's restructured program creates distinct tiers based on researcher history. Established researchers with proven track records retain access to higher payouts and faster review, while newcomers must demonstrate value before receiving similar treatment.

The shift reflects a broader tension in security research as AI tools democratize access but also generate noise. Bug bounty programs must balance encouraging new talent against maintaining operational capacity to review submissions effectively.

sources
more in Security
California aftermarket car security systems vulnerable to Bluetooth hijacking via shared encryption key Millions of vehicles with dealer-installed KARR/SWDS security systems use identical Bluetooth encryption keys, allowing attackers to unlock and start cars remotely. Zimbra zero-click vulnerability exploited by Russian state hackers for email theft The Russian group Laundry Bear combines phishing with a patched Zimbra flaw to access email without user interaction, targeting organizations still running vulnerable servers. Oracle ships 1,449 security patches in quarterly update as AI-driven vulnerability discovery accelerates The patch volume reflects AI tools finding vulnerabilities faster than human researchers, forcing defenders to manage larger workloads quarterly.