/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Facebook says it has received 15K bug reports in 2019, awarded about $2.2M in bounties for 1,300 of them, up from ~$1.1M for 700 bugs in 2018

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

Facebook's bounty spending doubled year over year — about $2.2M for 1,300 valid reports in 2019 versus roughly $1.3M paid to 321 researchers in 2014 — and the program had already widened its aperture before the 2019 tally: the 2018 expansion to third-party apps leaking Facebook user access tokens and the Data Abuse Bounty for app-developer misuse both pushed payouts beyond Facebook's own code.

The 2019 numbers sit mid-arc: the following year Wired reported the program, then in its 10th year, paying $1.98M on 1,000-plus submissions, and Facebook launched the Hacker Plus loyalty scheme to reward repeat hunters. The doubling signals Facebook treating external researchers as standing security infrastructure rather than ad-hoc help.

First-order effects

  • The researchers behind the roughly 1,300 accepted 2019 reports share about $2.2M — roughly double the 2018 pool — while Facebook's security team absorbed 15,000 submissions, meaning triage and validation capacity, not money, becomes the binding constraint.

Second-order effects

  • Rival platforms face pressure to match Facebook's payout scale and scope, since hunters rationally route findings to the program that pays fastest and widest — a dynamic Facebook reinforced by extending bounties to third-party apps handling its access tokens.

Third-order effects

  • If the pattern holds, bug bounty programs consolidate into loyalty-driven platforms — Facebook's own Hacker Plus is the template — where retention perks, not per-bug fees, decide where top researchers report, and external hunters become a permanent outsourced security layer for large platforms.

The trend: Big-platform bug bounties are scaling from ad-hoc reward pools into loyalty-based programs that compete for researchers' attention the way platforms compete for users.