GitHub says it is changing its vulnerability disclosure and bug bounty program starting July 27 after a large volume of AI-generated, “copy-paste” bug reports slowed its security review workflow. According to the reports, the company is restructuring payouts and how researchers participate. Public and open submissions are separated from an invite-only VIP tier. Public payout amounts decrease for multiple severity levels: critical findings are reported to drop to $10,000 from $30,000, high findings to $5,000, medium to $2,000, and low to $250. One outlet also reports that the largest rewards shift into an invite-only tier that is expected to pay significantly more—described as roughly 3–4 times higher than public payouts. For researchers submitting through the new public process, a HackerOne-related submission limit is cited, including a signal cap of four submissions. Overall, the changes aim to increase the volume of higher-quality reports while reducing the backlog created by low-effort automated submissions.