October 10, 2026
GitHub Halved Its Bug Bounty Payouts. The People Who Lose Most Arenβt the Ones You Think.
A two-tier market is forming. Beginners are being asked to prove themselves with the same tools that made proving yourself impossible.

By Riya Limba
4 min read
A two-tier market is forming. Beginners are being asked to prove themselves with the same tools that made proving yourself impossible.
I read the Axeploit analysis on a Friday afternoon and felt something I hadn't expected: recognition.
Not because I'd experienced what it described. Because I'd been living it without knowing what to call it.
On July 27, 2026, GitHub cut every public bug bounty payout by at least 50% . Critical findings dropped from $20,000β$30,000+ to a flat $10,000. Highs fell from up to $20,000 to $5,000. Mediums from up to $5,000 to $2,000. Lows from around $1,000 to $250.
But the payout cut isn't the story. The two-tier market that replaced it is.
The Two-Tier Market Nobody Voted For
GitHub didn't just reduce payouts. It split researchers into two classes.
Public tier: Lower payouts. A HackerOne signal requirement. A cap of four initial submissions to establish a track record before getting unrestricted access.
Invite-only VIP tier: The old payouts, or higher. $30,000+ for criticals. $20,000 for highs. $7,500 for mediums. $1,000 for lows.
VIP qualification is explicit and cumulative: one accepted critical, or two highs, or four mediums, or seven lows in GitHub's program .
I read that list four times.
To qualify for the tier where payouts are worth pursuing, you need to have already succeeded in the tier where payouts are barely worth pursuing.
It's a closed loop. And it's the same pattern I've been watching play out across the entire bug bounty economy.
The Math of Entry
Let's walk through what this looks like for someone starting now.
You submit your first report. You have four submissions to establish a track record. If any of them are duplicates, or out of scope, or "not exploitable" β the same outcome I've experienced β that's one of your four gone.
If you burn through all four without a single accepted finding, you're locked out. No unlimited access. No VIP tier. No path forward except starting over with a new account, if the platform even allows that.
To reach VIP status through the "seven lows" path, you need seven accepted low-severity findings. At $250 each in the public tier, that's $1,750 β assuming all seven get accepted. That's months of work for less than a single medium payout in the old system.
The math doesn't just discourage beginners. It structurally excludes them.
Why This Happened
The context matters, and the Axeploit analysis lays it out clearly.
HackerOne reported an industry-wide report volume surge of more than 100% in May 2026, after more capable AI tools shipped. Bugcrowd's triage queue grew 334% in a single three-week stretch in March, almost entirely low-quality submissions. Bugcrowd's team coined the term "sloptimism" β reports submitted fast and hopefully, with the author trusting the model's output more than the evidence .
GitHub's sequence shows the escalation. In May 2026, it required working proofs of concept, demonstrated impact, and pre-submission validation. The queue kept growing. Five weeks later, the full restructuring was announced .
The Axeploit analysis puts it bluntly: "Intake rules failed, so pricing and access controls took the load instead."
Triage time is the real currency. Convincing content became cheap to generate. Checking whether that content is correct did not become cheaper at all .
The Talent Pipeline Nobody Is Protecting
Here's what bothers me most about the two-tier system.
The researchers who qualify for VIP already have track records. They've been doing this for years. They have CVEs, Hall of Fame entries, and a reputation that makes triagers read their reports first.
The researchers who don't qualify are the ones still learning. The ones who need a path to build a track record. The ones who might become VIP researchers in two or three years, if they don't quit first.
The two-tier system doesn't just filter out slop. It filters out beginners.
And it does this at the exact moment when AI has made it harder than ever for a beginner's report to stand out from the noise. The slop problem that caused the restructuring is also the problem that makes it almost impossible for a legitimate beginner to prove themselves within four submissions.
What I'm Doing Differently
I can't change the two-tier market. I can't undo GitHub's decision. I can't make triagers read my report more carefully.
But I can change how I approach the problem.
First, I'm treating the first four submissions like they're the only four I'll ever get. Not because I'm dramatic. Because for some programs, they might be. Every report needs to be reproducible in five minutes, clear in one read, and impossible to confuse with AI slop.
Second, I'm looking for programs that haven't adopted two-tier systems yet. The Axeploit analysis notes that GitHub was the fourth major program to restructure, suspend, or narrow scope in 2026, after Google, Bugcrowd, and HackerOne's Internet Bug Bounty Program . But not every program has done this. Some still have open doors. I'm spending my time there.
Third, I'm remembering that the VIP tier exists. It's not a wall. It's a ladder. The rungs are small β one critical, two highs, four mediums, seven lows. I don't need to jump to the top. I just need to find one rung I can reach.
Seven lows. That's seven accepted findings. It's not nothing. But it's not impossible either.
The Uncomfortable Truth
GitHub cut its payouts by 50%. That's the headline. But the real story is the structure that replaced the old system.
A two-tier market where beginners are asked to prove themselves in the tier that pays least, using tools that make proving yourself hardest.
I've found one confirmed bug. I'm waiting to be paid. I don't know if I'll ever qualify for GitHub's VIP tier.
But I know what the ladder looks like now. And I know which rung I'm aiming for.
If you're also navigating the two-tier bug bounty market as a beginner, I write about what I'm actually figuring out β frustration included. Follow for more field notes from the bottom of the learning curve.