Microsoft Bug Bounty Program Unveils $20 Million Payout to 500 Security Researchers

www.news4hackers.com-microsoft-bug-bounty-program-unveils-20-million-payout-to-500-security-researchers-microsoft-bug-bounty-program-unveils-20-million-payout-to-500-security-researchers

Microsoft’s bug bounty initiatives have distributed over $20 million to security researchers in the past fiscal year, highlighting growing engagement and financial incentives in cybersecurity.

Key Statistics from Microsoft’s Bug Bounty Program

Microsoft reported receiving 2,531 vulnerability disclosures through its 15 distinct programs between July 1, 2025, and June 30, 2026. These reports came from professionals in 64 countries, with 562 individuals compensated for their contributions.

Breakdown of Payments and Initiatives

The highest single payment amounted to $200,000. Additional funds included $2.3 million allocated during the Zero Day Quest hacking competition and $800,000 distributed via new projects targeting third-party and open-source code vulnerabilities.

Reasons for Increased Submissions

Microsoft attributed the surge in submissions during the latter half of the year to heightened researcher engagement and the increasing integration of artificial intelligence in security analysis.

Historical Payout Trends

Previous annual payouts totaled approximately $17 million for 2024 and 2025, with $13 million disbursed annually between 2020 and 2023.

Criticisms and Controversies

Despite the program’s growth, some researchers have criticized Microsoft’s handling of vulnerability reports. A researcher operating under the alias Chaotic Eclipse has publicly shared details of multiple zero-day flaws without allowing Microsoft to address them. Certain of these vulnerabilities were later exploited in real-world attacks.

Chaotic Eclipse alleged that the company failed to properly manage reports, ignored communication attempts, delayed payments, removed the researcher’s account, and violated a prior agreement.



About Author

en_USEnglish