Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft’s Bug Bounty Program Soars to New Heights, Paying Out Over $20 Million to Researchers

In a major milestone for cybersecurity research, Microsoft has announced that it paid out more than $20 million through its bug bounty programs over the past year. The company received 2,531 eligible reports from researchers across 64 countries, with 562 researchers awarded a total of over $20 million in payouts. This significant increase in submissions and rewards demonstrates the growing importance of collaboration between tech companies and security researchers.

One notable aspect of Microsoft’s bug bounty program is its increasing use of AI to support security research. The company attributed the surge in submission volume during the second half of the year to both strong engagement from the research community and the growing adoption of AI tools for vulnerability hunting. This trend highlights the evolving role of artificial intelligence in cybersecurity, which can help streamline and improve the process of identifying vulnerabilities.

However, not all researchers are pleased with Microsoft’s handling of vulnerability reports. Chaotic Eclipse, a researcher who has previously worked with the company, has expressed dissatisfaction with Microsoft’s management of bug bounty submissions. The researcher alleged that the company mishandled several zero-day vulnerabilities, ignored communications, and breached prior agreements. This controversy raises questions about the responsibility of tech companies to engage with security researchers in a transparent and collaborative manner.

The success of Microsoft’s bug bounty program is also reflected in its comparison to previous years. The company paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023. This increase demonstrates the growing importance of bug bounty programs for companies looking to strengthen their security posture.

Interestingly, Microsoft’s bug bounty program also includes initiatives targeting vulnerabilities in third-party and open-source code. The company paid out $800,000 through these new initiatives, highlighting its commitment to addressing potential weaknesses across its software ecosystem.

As more companies engage with security researchers and adopt AI-powered vulnerability hunting tools, the importance of responsible disclosure and collaboration cannot be overstated. Microsoft’s success in its bug bounty program serves as a model for other tech companies looking to prioritize cybersecurity research and development.

In light of this story, we urge readers to consider the following takeaway: if you’re working with a company on a bug bounty program or similar initiative, make sure to clearly understand the terms and expectations. Keep detailed records of your submissions and communications, and don’t hesitate to speak up if you feel that your concerns are being ignored. By promoting transparency and collaboration, we can all contribute to a more secure online environment.


Source: SecurityWeek — 2026-08-04