Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

Key points
- Microsoft paid out more than $20 million through its bug bounty programs between July 2024 and June 2025.
- 562 researchers submitted 2,531 valid vulnerability reports across 15 separate programs.
- The single largest payout was $200,000 for one report.
- Payouts have risen sharply: roughly $13 million per year from 2020 to 2023, then $17 million in 2024 and 2025, now $20 million.
- One researcher publicly released unpatched flaws after accusing Microsoft of ignoring reports and withholding payments.
Microsoft this week said it paid more than $20 million to outside security researchers over the past year, the largest annual total in the company's bug bounty history. Bug bounty programs are formal schemes where a company invites independent researchers to find security flaws and pays them a reward for each valid report, rather than waiting for criminals to find the same weaknesses first.
The money went to 562 researchers. They came from 64 countries and submitted 2,531 reports that Microsoft judged to be genuine, exploitable flaws.
What did researchers actually find and earn?
The top single payment was $200,000. That figure rewards a report describing a flaw serious enough that Microsoft considered the information worth that sum to receive privately rather than have it surface elsewhere.
Two pools of money sit inside the $20 million headline figure. One is $2.3 million paid to participants at Zero Day Quest, a live hacking contest Microsoft runs where researchers compete to find flaws in real time. The second is $800,000 from newer programs that extend the bounty to weaknesses found in third-party software and open-source code that ships as part of Microsoft products.
| Period | Annual payout |
|---|---|
| 2020 to 2023 (each year) | approx. $13 million |
| 2024 to 2025 | approx. $17 million |
| July 2024 to June 2025 | over $20 million |
Microsoft credited the jump in submission volume partly to researchers making greater use of AI tools, meaning artificial intelligence software that can help scan code and spot potential vulnerabilities faster than a person working alone.
Is there a dispute behind the numbers?
Yes, and it is significant. A researcher known online as Chaotic Eclipse, also referred to as Nightmare Eclipse, has publicly released details of several unpatched vulnerabilities without first giving Microsoft time to fix them. Some of those flaws were later found being actively exploited by criminals, first reported by SecurityWeek.
Chaotic Eclipse has publicly accused Microsoft of mishandling reports, going silent on communications, deleting the researcher's reporting account, withholding bounty payments, and breaking a prior agreement. Microsoft has not publicly addressed those specific allegations.
When a researcher releases vulnerability details before a patch exists, it is called a zero-day disclosure, meaning attackers can use the information immediately because no fix is available yet. That outcome, whatever caused it, puts ordinary users at risk.
Should ordinary people care about this?
Directly, yes. Every flaw these researchers find and report privately is one that criminals cannot quietly exploit against the computers, phones, and services most people use every day. Paying researchers well is one of the more straightforward ways a large software company can reduce real-world harm.
If you use Windows, Microsoft 365, or any Microsoft product, keeping automatic updates switched on remains the most useful thing you can do. Patches for the flaws these researchers report arrive through those updates.



