Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.

Microsoft security

Microsoft announced on Monday that over the past year it has paid out more than $20 million through its bug bounty programs.

Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries.

Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000.

[ Read: Will AI Kill the Bug Bounty Industry? ]

The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code

Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”.

Advertisement. Scroll to continue reading.

Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023.

While the latest numbers show that Microsoft’s bug bounty programs are increasingly successful, not all researchers are happy with the company’s handling of vulnerability reports.

A researcher who uses the online moniker Chaotic Eclipse and Nightmare Eclipse has released the details of several zero-days without giving Microsoft the chance to patch them. Some of the flaws ended up being exploited in the wild

Chaotic Eclipse has voiced strong dissatisfaction with Microsoft, alleging that the company mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account, and breached a prior agreement.

Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

Related: Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

Related: Meta Paid Out $4 Million via Bug Bounty Program in 2025

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.