Google says it paid $6.7M in 2020, up from $6.5M in 2019, to 662 researchers from 62 countries as part of its bug bounty program
Catalin Cimpanu / ZDNet : Source: Google Online Security Blog .
Context & Ripple Effects
Google's annual bug bounty disclosure has become a year-over-year series worth reading for its shape, not any single number: payouts climbed from $2.9M across 274 researchers in 2017 to $6.5M across 461 researchers in 2019, and the 2020 figure extends that curve to $6.7M and 662 researchers spanning 62 countries.
The interesting tension is inside the totals: average payment per researcher fell from roughly $14K in 2019 to about $10K in 2020 even as the headcount grew by 200 — Google is broadening the funnel faster than it is raising the ceiling, a pattern the later 2021 jump to $8.7M and the mid-2021 launch of Bug Hunters University suggest it was actively managing.
First-order effects
- 662 security researchers across 62 countries now have a direct paid relationship with Google, and the 200-researcher year-over-year expansion means more of the program's value flows to first-time and lower-tier finders rather than repeat top earners.
Second-order effects
- A wider, geographically distributed researcher pool raises the odds that Chrome, Android, and server-side flaws surface through Google's program before black-market buyers see them, tightening the supply of exploitable bugs available to anyone else.
Third-order effects
- If the disclosure cadence holds — 2017, 2019, 2020, then $10M to 632 researchers in 2023 — annual bounty reporting functions as a standing benchmark that pressures every large platform operator to publish comparable numbers or explain why it won't.
The trend: Bug bounties are consolidating into a formalized, annually reported labor market for vulnerability discovery, with platform vendors competing on researcher reach rather than headline payouts alone.