Google says in 2019 its bug bounty program paid 461 security researchers $6.5M, up from $3.4M to 317 researchers in 2018
Google today announced it has paid out over $21 million since launching its bug bounty program in November 2010. In the past year alone, the company distributed $6.5 million …
Context & Ripple Effects
This disclosure slots into a steady escalation arc: Google's 2017 payout was $2.9M to 274 researchers and 2018's was $3.4M to 317, so the 2019 jump to $6.5M across 461 researchers is the year the program's spend nearly doubled. The cumulative figure passed $21M since the November 2010 launch, up from $12M just two years earlier.
The pattern held after this report: $6.7M to 662 researchers in 2020, $8.7M to 696 in 2021, and $10M to 632 in 2023 — making the 2019 report the inflection point where Google turned an annual payout disclosure into a recurring benchmark.
First-order effects
- The 461 researchers who filed valid bugs in 2019 saw per-program payouts roughly double year over year, and Google's security teams absorbed the resulting influx of vulnerability reports.
Second-order effects
- Rising payouts set a de facto market rate for high-severity web and Android vulnerabilities, pressuring smaller vendors' bounty programs to raise their own top-end rewards to keep researchers from concentrating on Google's surface — the researcher pool itself grew from 317 to 662 across 2019-2020.
Third-order effects
- With Google later adding Bug Hunter University as a training pipeline on top of the reward program, bug bounties are hardening from ad-hoc payouts into standing, budgeted external security infrastructure — with annual payout disclosures serving as a competitive metric across the industry.
The trend: Big-tech bug bounty spending is compounding into a normalized line item in security budgets, with Google's annual disclosure cadence functioning as the industry's reference point.