As artificial intelligence (AI) tools become increasingly adept at identifying software vulnerabilities, they have also contributed to a surge of AI-generated reports that often contain no real issues. This situation has generated frustration among developers, notably Linux founder Linus Torvalds, who expressed his dissatisfaction with the flood of irrelevant AI-generated bug reports. The challenge became so overwhelming for one open-source project that it had to suspend its bug bounty program entirely. GitHub now follows suit by revising its own bug bounty initiatives in response to the rising tide of AI reports.
GitHub: How the New Bug Bounty Program Works
In their official announcement, GitHub outlined a dual-tier system for the revised Bug Bounty Program. Initially, a VIP tier will be introduced, allowing bug hunters who provide consistently high-quality reports demonstrating significant impact to qualify. Benefits for this VIP status include higher monetary rewards and expedited communication with GitHub developers.
For lower-risk vulnerabilities, VIPs can earn $1,000. The reward scales with the potential risk to the platform, with critical security flaws fetching rewards of $30,000 or more. To qualify as a VIP, hunters must meet criteria including the discovery of a critical vulnerability or multiple high- or medium-risk bugs, ensuring that only serious contributors receive enhanced benefits.
Public Program Adjustments
Alongside the exclusive VIP program, GitHub will maintain a public bounty program accessible to all bug hunters. However, rewards will be reduced to prioritize quality over quantity. Minor vulnerabilities now offer rewards starting at $250, a drop from previous ranges of $617 to $2,000. For critical vulnerabilities, the cap has also been lowered to $10,000, previously set at $20,000 to $30,000.
Importantly, specific limitations for aspiring bug hunters have been introduced. New contributors can report a maximum of four bugs initially, with this limit enforced through the HackerOne platform. GitHub clarifies that this is not intended as a barrier for new researchers but rather a means to allow them to demonstrate genuine findings and showcase their skills. Only after proving themselves will they be eligible to report more vulnerabilities.
The Impact of AI on Bug Reporting
The surge of AI-influenced reports signifies a broader issue within the security landscape. While AI tools can expedite the detection of faults, their misuse poses a challenge that companies must address. GitHub’s restructuring is a crucial step in ensuring that genuine vulnerabilities are prioritized, safeguarding the integrity of open-source projects. The move aims to foster a more effective and reliable bug reporting ecosystem that discourages unproductive contributions.
As the software landscape evolves with AI playing a significant role, the tech community must remain vigilant. The adjustments to GitHub’s bug bounty program are emblematic of proactive approaches taken by companies to manage AI’s impact while encouraging valuable contributions from ethical hackers and developers alike.

