/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says its bug bounty program paid $13.6M to 341 security researchers in the past 12 months, down slightly from the $13.7M it paid a year ago

Microsoft said it awarded more than $13.6 million as monetary rewards to security researchers through its public bug bounty programs over the past 12 months.

The Record Catalin Cimpanu

Context & Ripple Effects

Microsoft's bounty machine has scaled fast: from the [[a:940369|HackerOne partnership era, when 2018 awards topped $2M and the maximum per-bug payout rose from $15K to $50K]], to a ~$13.7M run rate that has now plateaued, with the latest 12 months at $13.6M across 341 researchers. The flat year-over-year figure lands while the researcher pool itself is consolidating around a few high earners.

The competitive frame is Google, whose program pays fewer dollars but reaches far more people: $6.7M across 662 researchers from 62 countries in 2020, versus Microsoft's 341 recipients for roughly double the money. The corpus's later data point — $17M to 344 researchers across 59 countries by mid-2025, with a $200K top reward — shows where the per-bug ceiling was headed.

First-order effects

  • 341 security researchers share a $13.6M pool that did not grow year over year, so average and top-end per-researcher earnings depend entirely on severity tiering rather than volume of findings.
  • Microsoft's disclosure gives rivals a public benchmark: Google's program already pays out to roughly twice as many researchers for about half the money, making researcher reach, not total spend, the visible differentiator.

Second-order effects

  • Programs compete for the same elite bug hunters on payout ceilings and speed, pressuring Microsoft to keep raising maximum rewards — a path it started in 2019 at $50K and that later reached a $200K top award — rather than broadening the recipient base.
  • A flat budget against a growing attack surface shifts more of the burden to internal security teams and automated tooling, since external researchers are being paid the same to cover more product area.

Third-order effects

  • If the pattern holds, bug bounty spending consolidates around fewer, higher-paid specialists for critical findings, turning top-tier vulnerability research into a professionalized market with escalating per-bug prices.
  • Annual bounty disclosures become a standard transparency ritual among hyperscalers — Microsoft and Google both now report yearly totals — letting buyers and regulators compare security investment across platforms.

The trend: Corporate bug bounty programs are shifting from broad researcher participation toward fewer, much larger payouts for high-severity findings, with annual disclosure totals becoming a competitive benchmark.

Discussion

  • @msftsecresponse @msftsecresponse on x
    Microsoft Bug Bounty Programs awarded $13.6M to 341 security researchers in the last 12 months. Thank you to everyone for your continued work to help secure millions of customers. https://msrc-blog.microsoft.com/ ...
  • @thegrugq Thaddeus E. Grugq on x
    ...too bad it wasn't enough. https://twitter.com/...
  • @haifeili Haifei Li on x
    My view: unbelievable with such a big payout MSFT still: - No love for Office research (msft revenue generator) - No love for enterprise server-side research (hello, #proxylogon) - No love for creative attack vector/surface research (in the spirit of hacking - go deeper) https://…
  • @tiraniddo James Forshaw on x
    Perhaps they should pay an extra bounty every time they screw up the fix as an incentive 😁 https://twitter.com/...