Google says it paid $6.7M in 2020, up from $6.5M in 2019, to 662 researchers from 62 countries as part of its bug bounty program
Sum is up from the $6.5 million the company paid security researchers a year before, in 2019. — Google said today it paid more than $6.7 million … Source: Google Online Security Blog .
Context & Ripple Effects
Google's annual payout disclosure has become a running series: $2.9M to 274 researchers in 2017, then $6.5M to 461 researchers in 2019, and now $6.7M to 662 researchers from 62 countries in 2020. The headcount is growing faster than the dollar figure — per-researcher payouts are compressing even as the program widens its global reach.
The steady year-over-year announcements matter because they turn vulnerability discovery into a measurable, budgeted line item at Google rather than an ad-hoc goodwill gesture — a template rivals are increasingly expected to match.
First-order effects
- 662 security researchers across 62 countries now have a recurring revenue relationship with Google, giving independent hunters a predictable income stream tied to Chrome, Android, and Google's server-side code.
- Google gains a published, comparable metric — dollars paid and bugs found — that it can use each February to signal the scale of its external security audit surface.
Second-order effects
- Rival platform vendors face pressure to publish equivalent annual figures or appear less transparent about their own vulnerability pipelines, since Google has normalized the yearly disclosure format.
- The widening researcher pool raises the going rate for elite hunters: as more vendors run bounties, top researchers can arbitrage between programs, pushing Google toward higher maximum awards to retain them.
Third-order effects
- If the pattern holds — payouts roughly doubling every few years alongside expanding researcher counts — crowdsourced vulnerability discovery becomes a structural component of big-platform security budgets, effectively outsourcing part of the red-team function to a global freelance workforce.
- Annual disclosure norms like this one give regulators and enterprise buyers a benchmark for judging vendor security maturity, making participation in well-funded bounty programs a de facto requirement for large consumer platforms.
The trend: Big-platform bug bounty programs are scaling into permanent, globally distributed security-audit workforces whose annual payout disclosures double as competitive signaling.