Facebook says it has received 15K bug reports in 2019, awarded about $2.2M in bounties for 1,300 of them, up from ~$1.1M for 700 bugs in 2018
Lily Hay Newman / Wired :
Context & Ripple Effects
Facebook's bounty spending doubled year over year — about $2.2M for 1,300 valid reports in 2019 versus roughly $1.3M paid to 321 researchers in 2014 — and the program had already widened its aperture before the 2019 tally: the 2018 expansion to third-party apps leaking Facebook user access tokens and the Data Abuse Bounty for app-developer misuse both pushed payouts beyond Facebook's own code.
The 2019 numbers sit mid-arc: the following year Wired reported the program, then in its 10th year, paying $1.98M on 1,000-plus submissions, and Facebook launched the Hacker Plus loyalty scheme to reward repeat hunters. The doubling signals Facebook treating external researchers as standing security infrastructure rather than ad-hoc help.
First-order effects
- The researchers behind the roughly 1,300 accepted 2019 reports share about $2.2M — roughly double the 2018 pool — while Facebook's security team absorbed 15,000 submissions, meaning triage and validation capacity, not money, becomes the binding constraint.
Second-order effects
- Rival platforms face pressure to match Facebook's payout scale and scope, since hunters rationally route findings to the program that pays fastest and widest — a dynamic Facebook reinforced by extending bounties to third-party apps handling its access tokens.
Third-order effects
- If the pattern holds, bug bounty programs consolidate into loyalty-driven platforms — Facebook's own Hacker Plus is the template — where retention perks, not per-bug fees, decide where top researchers report, and external hunters become a permanent outsourced security layer for large platforms.
The trend: Big-platform bug bounties are scaling from ad-hoc reward pools into loyalty-based programs that compete for researchers' attention the way platforms compete for users.