Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year

More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A security researcher at a laptop surrounded by screens displaying code and vulnerability reports, with payment notification windows visible, photoreal office s
Share

Key points

  • Microsoft paid out more than $20 million through its bug bounty programs between July 2024 and June 2025.
  • 562 researchers submitted 2,531 valid vulnerability reports across 15 separate programs.
  • The single largest payout was $200,000 for one report.
  • Payouts have risen sharply: roughly $13 million per year from 2020 to 2023, then $17 million in 2024 and 2025, now $20 million.
  • One researcher publicly released unpatched flaws after accusing Microsoft of ignoring reports and withholding payments.

Microsoft this week said it paid more than $20 million to outside security researchers over the past year, the largest annual total in the company's bug bounty history. Bug bounty programs are formal schemes where a company invites independent researchers to find security flaws and pays them a reward for each valid report, rather than waiting for criminals to find the same weaknesses first.

The money went to 562 researchers from 64 countries who submitted 2,531 reports that Microsoft judged to be genuine, exploitable flaws.

What did researchers actually find and earn?

The top single payment was $200,000, a figure that reflects what Microsoft considers the information worth to receive privately. Two pools sit inside the $20 million total: $2.3 million paid to participants at Zero Day Quest, a live hacking contest where researchers compete to find flaws in real time, and $800,000 from newer programs covering weaknesses in third-party software and open-source code that ships as part of Microsoft products.

Period Annual payout
2020 to 2023 (each year) approx. $13 million
2024 to 2025 approx. $17 million
July 2024 to June 2025 over $20 million

Microsoft credited the jump in submission volume partly to researchers making greater use of AI tools, meaning artificial intelligence software that can help scan code and spot potential vulnerabilities faster than a person working alone. That's a dynamic we've been tracking: our 22 July story on GitHub cutting its public bounty payouts raised the same question of whether AI-assisted research is reshaping how platforms value independent finders.

Is there a dispute behind the numbers?

Yes. A researcher known online as Chaotic Eclipse, also referred to as Nightmare Eclipse, has publicly released details of several unpatched vulnerabilities without first giving Microsoft time to fix them. Some of those flaws were later found being actively exploited by criminals, first reported by SecurityWeek.

Chaotic Eclipse has accused Microsoft of mishandling reports, going silent on communications, deleting the researcher's reporting account, withholding payments, and breaching a prior agreement. Microsoft hasn't publicly addressed those specific allegations.

When a researcher releases vulnerability details before a patch exists, attackers can use the information immediately because no fix is available. That outcome, whatever caused it, puts ordinary users at risk.

Should ordinary people care about this?

Directly, yes. Every flaw these researchers find and report privately is one that criminals can't quietly exploit against the computers and services most people rely on daily. Paying researchers well is one of the more straightforward ways a large software company can reduce real-world harm.

The Chaotic Eclipse situation is the number worth watching here, not the $20 million headline. A breakdown between a company and a researcher that ends in unpatched public disclosures and active exploitation is the failure mode the entire bug bounty model exists to prevent. If you run Windows or any Microsoft product, keeping automatic updates switched on is the most useful thing you can do: patches for the flaws these researchers report arrive through those updates.

© 2026 Threat Vectr