Restructuring GitHub's bug bounty program
Posted by soheilpro 2 days ago
Comments
Comment by wxw 2 days ago
> VIP program bounty table:
Severity Payout
-------- --------
Low $1,000
Medium $7,500
High $20,000
Critical $30,000+
> We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.> Our new public program bounty table:
Severity Payout
-------- -------
Low $250
Medium $2,000
High $5,000
Critical $10,000
> To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.Comment by cobertos 1 day ago
Almost as though they want the quality and consistency of hired labor but not the cost
Comment by krystalgamer 1 day ago
also given that nowadays most bounty hunters have some level of automation don't see the issue of getting paid by the task instead of the by the hour. diversification of source of income is always good :)
Comment by dinkelberg 2 days ago
Comment by toomuchtodo 2 days ago
Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.
Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)
Comment by tancop 1 day ago
Comment by super256 2 days ago
So, researchers first need to collect some positive rep. But the rep points are global, so once you have fixed a few bugs for Google, you've gotten enough +rep that you can also receive stuff at GitHub.
Oh, and ID check when signing up at H1.
Long term all beg bounty submitters would be banned for pretty much all of tech.
Comment by Synthetic7346 2 days ago
Comment by ofjcihen 1 day ago
Comment by applfanboysbgon 2 days ago
Comment by dfedbeef 2 days ago
Comment by sevenseacat 1 day ago
Comment by applfanboysbgon 2 days ago
Comment by account42 1 day ago
Comment by inigyou 1 day ago
Comment by blackqueeriroh 1 day ago
Comment by toomuchtodo 1 day ago
Comment by greatgib 1 day ago
If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...
Comment by everfrustrated 1 day ago
Why take the lower offer by going directly.
That sounds like a win for everyone involved.
Comment by htrp 1 day ago
this is formalizing some very enterprise-esque processes for security research, software resellers anyone?
Comment by saagarjha 2 days ago
Comment by w0m 1 day ago
Comment by applfanboysbgon 2 days ago
Comment by Klaster_1 2 days ago
Comment by darkamaul 2 days ago
Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.
Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.
Comment by poly2it 1 day ago
Comment by Schnitz 2 days ago
Comment by sdevonoes 1 day ago
Comment by embedding-shape 1 day ago
Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?
Comment by account42 1 day ago
Comment by embedding-shape 1 day ago
Comment by frizlab 1 day ago
Comment by nullsanity 2 days ago
Comment by fragmede 2 days ago
Comment by 2001zhaozhao 2 days ago
Instead, now you probably need to be actually vetting your bug reports yourself so that a large percentage of them are real, before they let you in the verified program, where you get a normal amount of payout.
So it incentivizes high quality AI bug spamming (if you can manage it) over low quality AI bug spamming. In turn since less people are doing low quality AI bug spamming, Github gets to spend less time filtering the low quality reports.
Comment by jonoc 2 days ago