GitHub plans a two-tier bug bounty program that cuts rewards for the public and boosts payouts for invite-only researchers, amid a flood of AI-powered reports
Code shack also putting new limits on first-time researchers, and reserving the biggest rewards for a hand-picked group of proven hunters
Context & Ripple Effects
GitHub previously broadened its bounty incentives, including removing its maximum reward limit in a 2019 expansion of its public program. It also built a confidential reporting channel for open-source maintainers through private vulnerability reporting, making researcher intake a core part of its security posture.
The new segmentation follows a wider program-management problem: companies have been adding screening and AI-assisted triage as AI-generated reports strain bounty operations. GitHub is now applying that pressure directly to compensation and researcher access.
First-order effects
- Public and first-time researchers face lower potential rewards and tighter participation limits, while GitHub concentrates its largest payouts on a vetted invite-only cohort.
- GitHub can route scarce review capacity toward reports from researchers it already trusts, rather than treating all incoming submissions as equally economical to process.
Second-order effects
- Researchers who rely on open public bounty programs may shift attention toward vendors with less restrictive terms, while established hunters gain a stronger incentive to cultivate private-program access.
- Other bounty operators facing similar report volume may adopt more explicit tiers, vetting, and differentiated payouts rather than attempting to scale review teams with incoming submissions.
Third-order effects
- If this model spreads, bug bounties may become less of an open market for discovery and more of a managed supplier network in which reputation and prior access determine who can compete for top rewards.
- AI-assisted vulnerability discovery is likely to make report quality, reproducibility, and trusted researcher identity more important than raw submission volume, though the durability of that shift depends on whether triage automation improves enough to reopen programs.
The trend: AI is pushing vulnerability disclosure programs from broad, volume-based intake toward curated researcher networks and quality-controlled security testing.