Microsoft's Bug Bounty Program Pays Out Record $20M Amid AI-Powered Security Research Boom
Microsoft's bug bounty program has paid out a record-breaking $20 million to 562 researchers between July 1, 2025, and June 30, 2026. This surpasses last year's payout of $17 million to 344 researchers.
The company expanded its bug bounty program in December 2025, changing the rules to make critical vulnerabilities eligible for rewards if they had a direct impact on Microsoft's online services, even if the faulty code belonged to a third party or an open source project. This change accounted for $800,000 in additional rewards.
The increased number of reports can be attributed in part to the growing use of AI to support security research, with Microsoft also attributing its crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery. In July alone, 622 vulnerabilities were patched, surpassing the previous record of 206 set just a month earlier.
However, Microsoft's Executive VP of Windows + Devices Pavan Davuluri pointed out that the company offers customers automated patching tools to ease the burden. The company has also faced controversy amid unverified speculation that one prolific researcher may be a former Microsoft staffer, who began publishing zero-days outside coordinated disclosure after allegedly being insulted and humiliated by Microsoft's response to their attempts to report vulnerabilities.