Microsoft reported paying out over $20 million through its bug bounty programs between July 1, 2025, and June 30, 2026. This amount was distributed among 562 researchers who submitted 2,531 eligible vulnerability reports across 15 programs.
The total includes $2.3 million from the Zero Day Quest hacking contest and $800,000 for new initiatives targeting third-party and open-source code vulnerabilities. The largest individual payout reached $200,000.
The company noted a significant increase in submission volume during the latter half of the year. Microsoft attributes this rise to strong engagement from the research community and the growing use of AI to support security research.
This year's payout of over $20 million surpasses previous years, with approximately $17 million paid in 2024-2025 and around $13 million annually between 2020 and 2023.
Despite the increased payouts, some researchers have expressed dissatisfaction with Microsoft's handling of vulnerability reports. One researcher, known as Chaotic Eclipse, publicly released details of several zero-day vulnerabilities without prior patching by Microsoft, some of which were subsequently exploited.
Chaotic Eclipse has accused Microsoft of mishandling reports, ignoring communications, withholding bounty payments, deleting their reporting account, and breaching a prior agreement.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft announced it paid over $20 million through its bug bounty programs to 562 researchers from July 2025 to June 2026, marking an increase from previous years. This indicates a growing engagement in vulnerability research, but also highlights ongoing issues with researcher dissatisfaction regarding Microsoft's handling of reports.