/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Facebook paid 330 security researchers $1.5M in 2013; adds Instagram, Parse, Atlas, Onavo to Bug Bounty program

Facebook today announced it paid out $1.5 million to 330 security researchers around the world in 2013 as part of its bug bounty program, which launched back in August 2011.

The Next Web Emil Protalinski

Context & Ripple Effects

When Facebook launched its bug bounty program in August 2011, it moved fast enough to pay out $40,000 to hackers within the first three weeks. Two and a half years on, the same program dispersed $1.5 million to 330 researchers across 2013 — a scale shift that turned an experiment into a line item, and the story was picked up widely enough that both Bloomberg and ZDNet ran it the same day.

The more strategically telling move is the scope expansion: by folding Instagram, Parse, Atlas and Onavo under the bounty umbrella, Facebook is extending its paid-disclosure perimeter across every property it operates, so a flaw found anywhere in the portfolio routes to Facebook's security team rather than to a black-market buyer.

First-order effects

  • Instagram, Parse, Atlas and Onavo now carry the same cash rewards as facebook.com itself, immediately widening the attack surface independent researchers are financially incentivized to probe on Facebook's behalf.
  • The 330 researchers who earned $1.5 million in 2013 now have a demonstrated, repeatable revenue channel from responsible disclosure, raising the opportunity cost of selling equivalent findings elsewhere.

Second-order effects

  • Rival consumer web companies face pressure to stand up comparably funded bounty programs of their own, or cede first look at vulnerabilities in their own products to researchers whose best-paying customer is Facebook.
  • Every acquisition widens the perimeter the program must cover — the Oculus VR purchase announced April 1, 2014 alone adds an entirely new hardware-and-software stack whose bugs will eventually need the same reward structure.

Third-order effects

  • If annual payout disclosures become routine, they function as de facto industry benchmarks, normalizing crowdsourced vulnerability discovery as permanent security infrastructure rather than a goodwill gesture.
  • A professional class of full-time bug hunters organized around platform payout programs takes shape, shifting vulnerability economics from exploit markets toward vendor-funded disclosure.

The trend: Bug bounty programs are hardening from PR-friendly experiments into standing security infrastructure that scales with each new product a platform company absorbs.