Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft’s Bug Bounty Program Pays Out $20 Million to 500 Researchers Over the Past Year

In a significant milestone, Microsoft has announced that it has paid out over $20 million through its bug bounty programs since July 1, 2025. The company received an astonishing 2,531 eligible reports from researchers across 64 countries, with 562 individuals awarded payouts ranging from a few thousand dollars to a whopping $200,000.

The bug bounty program, which has been in place for several years, is designed to encourage security researchers to identify vulnerabilities in Microsoft’s products and services. In exchange for their findings, these researchers are rewarded with cash payments, recognition, and sometimes even job offers. The program has proven to be a huge success, with Microsoft paying out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023.

One notable aspect of this year’s bug bounty payouts is the significant increase in submission volume during the second half of the year. Microsoft attributed this surge to “strong engagement from the research community and the growing use of AI to support security research.” This trend suggests that the company’s efforts to engage with the security community and encourage vulnerability reporting are paying off.

However, not all researchers are happy with Microsoft’s handling of vulnerability reports. Chaotic Eclipse, a well-known security researcher, has publicly expressed dissatisfaction with the company’s handling of several zero-day vulnerabilities he discovered. According to his claims, Microsoft mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted his reporting account, and breached a prior agreement. While these allegations are serious, they do not seem to have had a significant impact on the overall success of Microsoft’s bug bounty program.

The success of Microsoft’s bug bounty program is a testament to the power of collaborative security research. By providing incentives for researchers to identify vulnerabilities, companies like Microsoft can ensure that their products and services are more secure, ultimately protecting users from potential attacks. As the threat landscape continues to evolve, it’s likely that bug bounty programs will play an increasingly important role in keeping software and systems safe.

So what does this mean for you? If you’re a security researcher or simply someone who cares about online safety, take note of Microsoft’s success with its bug bounty program. It shows that companies are willing to listen to the security community and reward those who help make their products more secure. Who knows – maybe one day your own vulnerability report will earn you a substantial payout!


Source: SecurityWeek — 2026-08-04