/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Facebook's bug bounty program, now in its 10th year, paid out $1.98M in 2020 so far, on over 1,000 submissions

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

Ten years in, Facebook's bug bounty has become a scaled institution rather than a side channel: from $1.3M to 321 researchers in 2014 — when Oculus was first folded in — through the 2018 expansion to third-party apps mishandling access tokens and a Data Abuse Bounty, to $2.2M for 1,300 accepted reports in 2019.

The 2020 figure of $1.98M on over 1,000 submissions lands just weeks after Facebook launched Hacker Plus, which layers bonuses and perks on top of per-bug payments based on past performance — signaling the program is now managed for researcher retention, not just vulnerability intake.

First-order effects

  • Security researchers weighing where to submit now face a two-layer incentive at Facebook — cash per accepted bug plus Hacker Plus status perks — weeks into the loyalty scheme's existence.
  • Facebook's security team gets a steadier pipeline: over 1,000 paid submissions in 2020 alone means external hunters are functioning as continuous outsourced QA for the platform.

Second-order effects

  • Rival platforms running their own bounty programs must match retention mechanics, not just payout sizes, or risk their best hunters concentrating effort on Facebook's higher-expected-value stack.
  • As scope keeps widening — access tokens, third-party apps, data misuse by developers — the effective cost of Facebook's ecosystem mistakes is partially mutualized with the research community, softening reputational hits from exposures it didn't directly cause.

Third-order effects

  • If the pattern holds, bug bounty matures from marketing-friendly gesture into standing security infrastructure, with platforms competing on researcher experience tiers the way they compete on developer tooling — and regulators gaining a de facto benchmark for what responsible disclosure at scale looks like.

The trend: Bug bounty programs are evolving from flat per-bug payouts into tiered, loyalty-based systems that treat independent security researchers as a long-term strategic workforce.

Discussion

  • @lilyhnewman Lily Hay Newman on x
    Facebook Messenger had a bug (now patched) that was similar to that FaceTime bug from last year in that an attacker could have started hearing audio from a target's end just by calling them...no pickup required https://www.wired.com/...
  • @techjournalist Sean Kerner on x
    There could well be more $$ on the table too for a bug bounty hunter. Facebook Messenger has the open source libjingle framework as its base...and where there is one bug there is almost always....more... https://twitter.com/...
  • @viss @viss on x
    i wonder what it will take for people to stop using these tools https://twitter.com/...
  • @natashenka Natalie Silvanovich on x
    My WebRTC state machine research continues https://twitter.com/...
  • @kimzetter Kim Zetter on x
    An attacker could simultaneously call a target and send specially crafted, invisible message to trigger the attack against Messenger for Android, allowing attacker to hear audio through victim's phone, even if they didn't answer call, for as long as phone rang https://twitter.com…
  • @zackwhittaker Zack Whittaker on x
    A bug in Facebook Messenger could have allowed an attacker to call you and start listening to your end before you picked up. @lilyhnewman scoop. https://www.wired.com/...