Google says it paid 274 security researchers $2.9M in 2017 as part of its bug bounty program, bringing total paid out to $12M since November 2010 launch
especially compared to the cost of a major data breach or hack. http://security.googleblog.com/ ...
Context & Ripple Effects
Google's 2017 tally — $2.9M to 274 researchers, $12M cumulative since the program's November 2010 launch — reads today as the early chapter of a decade-long scaling curve. The subsequent disclosures show the program more than tripling its annual outlay within six years: $6.5M to 461 researchers in 2019, then $8.7M to 696 researchers in 2021.
By 2023, Google was paying $10M a year to 632 researchers, with Android alone drawing $3.4M, and had layered on Bug Hunter University alongside a cumulative payout around $30M. The 2017 report matters because it established the annual-transparency cadence those later figures plug into.
First-order effects
- The 274 researchers who filed valid bugs in 2017 are paid against published rates, and Google converts outside security work into a predictable supply channel for fixes across Chrome, Android, and its web services.
Second-order effects
- Publishing the number annually turns the bounty into a benchmark: each year's disclosure sets the comparison point for the next, which is exactly how the program's growth from $2.9M to $10M became legible — and pressure-building — in the later reports.
Third-order effects
- If the pattern holds, coordinated vulnerability disclosure becomes a standing labor market rather than an ad-hoc reward: Google trains researchers through Bug Hunter University, pays by product area (Android's $3.4M slice shows where demand concentrates), and treats the outlay as routine security spend priced against breach costs.
The trend: Bug bounty programs are maturing into annualized, market-scale procurement of security research, with Google's payouts and researcher counts climbing steadily since 2010.