/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google says it paid $6.7M in 2020, up from $6.5M in 2019, to 662 researchers from 62 countries as part of its bug bounty program

Catalin Cimpanu / ZDNet : Source: Google Online Security Blog .

ZDNet Catalin Cimpanu

Context & Ripple Effects

Google's annual bug bounty disclosure has become a year-over-year series worth reading for its shape, not any single number: payouts climbed from $2.9M across 274 researchers in 2017 to $6.5M across 461 researchers in 2019, and the 2020 figure extends that curve to $6.7M and 662 researchers spanning 62 countries.

The interesting tension is inside the totals: average payment per researcher fell from roughly $14K in 2019 to about $10K in 2020 even as the headcount grew by 200 — Google is broadening the funnel faster than it is raising the ceiling, a pattern the later 2021 jump to $8.7M and the mid-2021 launch of Bug Hunters University suggest it was actively managing.

First-order effects

  • 662 security researchers across 62 countries now have a direct paid relationship with Google, and the 200-researcher year-over-year expansion means more of the program's value flows to first-time and lower-tier finders rather than repeat top earners.

Second-order effects

  • A wider, geographically distributed researcher pool raises the odds that Chrome, Android, and server-side flaws surface through Google's program before black-market buyers see them, tightening the supply of exploitable bugs available to anyone else.

Third-order effects

  • If the disclosure cadence holds — 2017, 2019, 2020, then $10M to 632 researchers in 2023 — annual bounty reporting functions as a standing benchmark that pressures every large platform operator to publish comparable numbers or explain why it won't.

The trend: Bug bounties are consolidating into a formalized, annually reported labor market for vulnerability discovery, with platform vendors competing on researcher reach rather than headline payouts alone.

Discussion

  • @bgurley Bill Gurley on x
    If your company doesn't have a bug bounty program, you are skipping the most tried and true method to shore up risks. Crowd-sourced security is now best practice. https://www.hackerone.com/ https://twitter.com/...
  • @nixcraft @nixcraft on x
    Amount of money Google paid to security researchers: A record-breaking payout of over $6.7 million in rewards, with an additional $280,000 given to charity https://security.googleblog.com/ ... https://twitter.com/...
  • @googlevrp @googlevrp on x
    Thank you to all bug hunters for your creativity, curiosity, and dedication in 2020! You made the impossible possible - once again. We are proud and grateful to have you. https://security.googleblog.com/ ...