Microsoft says its bug bounty program paid $13.6M to 341 security researchers in the past 12 months, down slightly from the $13.7M it paid a year ago
Microsoft said it awarded more than $13.6 million as monetary rewards to security researchers through its public bug bounty programs over the past 12 months.
Context & Ripple Effects
Microsoft's bounty machine has scaled fast: from the [[a:940369|HackerOne partnership era, when 2018 awards topped $2M and the maximum per-bug payout rose from $15K to $50K]], to a ~$13.7M run rate that has now plateaued, with the latest 12 months at $13.6M across 341 researchers. The flat year-over-year figure lands while the researcher pool itself is consolidating around a few high earners.
The competitive frame is Google, whose program pays fewer dollars but reaches far more people: $6.7M across 662 researchers from 62 countries in 2020, versus Microsoft's 341 recipients for roughly double the money. The corpus's later data point — $17M to 344 researchers across 59 countries by mid-2025, with a $200K top reward — shows where the per-bug ceiling was headed.
First-order effects
- 341 security researchers share a $13.6M pool that did not grow year over year, so average and top-end per-researcher earnings depend entirely on severity tiering rather than volume of findings.
- Microsoft's disclosure gives rivals a public benchmark: Google's program already pays out to roughly twice as many researchers for about half the money, making researcher reach, not total spend, the visible differentiator.
Second-order effects
- Programs compete for the same elite bug hunters on payout ceilings and speed, pressuring Microsoft to keep raising maximum rewards — a path it started in 2019 at $50K and that later reached a $200K top award — rather than broadening the recipient base.
- A flat budget against a growing attack surface shifts more of the burden to internal security teams and automated tooling, since external researchers are being paid the same to cover more product area.
Third-order effects
- If the pattern holds, bug bounty spending consolidates around fewer, higher-paid specialists for critical findings, turning top-tier vulnerability research into a professionalized market with escalating per-bug prices.
- Annual bounty disclosures become a standard transparency ritual among hyperscalers — Microsoft and Google both now report yearly totals — letting buyers and regulators compare security investment across platforms.
The trend: Corporate bug bounty programs are shifting from broad researcher participation toward fewer, much larger payouts for high-severity findings, with annual disclosure totals becoming a competitive benchmark.