GitHub is scaling back its bug bounty program by replacing cash rewards with swag for low-impact reports, citing a surge in AI-generated, low-quality submissions over the past year. The platform clarified that reports describing scenarios where users voluntarily interact with malicious content don't represent GitHub security failures. GitHub still welcomes AI-assisted research but requires human review before submission. The trend is industry-wide: Curl eliminated its bounty program, HackerOne paused payouts, Google restricted its OSS vulnerability rewards, and Linus Torvalds flagged the Linux kernel security list as nearly unmanageable due to AI-generated duplicate reports. Analysts warn the shift from cash to swag could shrink the pipeline of new security researchers, while benefiting experienced ones through faster triage and payouts.