Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
Microsoft announced on Monday that over the past year it has paid out more than $20 million through its bug bounty programs.
Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries.
Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000.
The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code.
Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”.
Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023.
While the latest numbers show that Microsoft’s bug bounty programs are increasingly successful, not all researchers are happy with the company’s handling of vulnerability reports.
A researcher who uses the online moniker Chaotic Eclipse and Nightmare Eclipse has released the details of several zero-days without giving Microsoft the chance to patch them. Some of the flaws ended up being exploited in the wild.
Chaotic Eclipse has voiced strong dissatisfaction with Microsoft, alleging that the company mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account, and breached a prior agreement.
This article was published by Security Week. Please check their website for the original content.