Microsoft Paid Over $20M to 562 Bug Researchers

Between July 1, 2025 and June 30, 2026, Microsoft awarded more than $20 million across 15 bug bounty programs to 562 researchers who filed 2,531 eligible reports.
Microsoft reported that between July 1, 2025 and June 30, 2026 it paid more than $20 million through 15 bug bounty programs. The company recorded 2,531 eligible vulnerability reports and awarded payments to 562 researchers from 64 countries.
The largest individual award reached $200,000. Microsoft allocated $2.3 million to participants in the Zero Day Quest contest and set aside about $800,000 for new initiatives targeting vulnerabilities in third-party and open source code. The company’s total award pool exceeded $20 million.
Microsoft noted a significant rise in submission volume during the second half of the reporting year, attributing the increase to stronger engagement from the security research community and wider use of AI tools to support research.
The 15 programs cover a range of Microsoft products and services. Microsoft reported it paid roughly $17 million in 2024 and 2025 and about $13 million per year from 2020 through 2023.
Not all researchers have accepted Microsoft’s handling of reports. A researcher using the monikers Chaotic Eclipse and Nightmare Eclipse released details of several zero-day vulnerabilities without providing Microsoft time to patch them; some of those flaws were later exploited in the wild. The researcher has alleged that Microsoft mishandled reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account and breached a prior agreement. Microsoft did not include detailed responses to those allegations in its payout announcement.
The company’s disclosure describes the size of its reward programs, the use of contests such as Zero Day Quest and new initiatives aimed at third-party and open source components. The report shows the company is using targeted incentives and expanded program coverage to encourage external reporting of security flaws.








