HackMyIP
← Back to News
2026-08-04 SecurityWeek

Microsoft Payouts Top $20M to 562 Bug Bounty Researchers in 2026

Bug BountyVulnerabilityZero-Day

Microsoft announced this week that its bug bounty programs have paid out more than $20 million to security researchers over the past year, marking the highest annual total in the company's history. Between July 1, 2025, and June 30, 2026, the tech giant received 2,531 eligible vulnerability reports through its 15 active bounty programs from researchers based in 64 countries. A total of 562 researchers received payouts, with the largest single award reaching $200,000. The figure includes $2.3 million distributed at the Zero Day Quest hacking contest and roughly $800,000 paid through newer initiatives focused on third-party and open-source code vulnerabilities. Researchers concerned about exposure from past data leaks can verify their credentials using an email breach checker.

Microsoft attributed a notable increase in submission volume during the second half of the reporting period to stronger community engagement and the growing adoption of AI-assisted security research tools. The upward trajectory is consistent with prior years, as Microsoft paid out approximately $17 million in 2024 and 2025 combined, and roughly $13 million per year between 2020 and 2023. The expansion of AI-driven vulnerability discovery has accelerated both the pace and breadth of submissions, with researchers increasingly leveraging large language models to identify flaws at scale.

Despite the program's growth, not all interactions between Microsoft and security researchers have been smooth. A researcher operating under the handles "Chaotic Eclipse" and "Nightmare Eclipse" publicly disclosed several zero-day vulnerabilities without coordinating disclosure, and some of the flaws were subsequently exploited in the wild. The researcher cited claims of mishandled reports, ignored communications, withheld bounty payments, a deleted reporting account, and breach of a prior agreement. The dispute highlights ongoing tension in the coordinated vulnerability disclosure process, particularly as AI accelerates the discovery-to-disclosure cycle.

Microsoft's $20 million milestone places it alongside other major bounty operators such as Google, which paid out $17 million in 2025, and Apple, which has distributed over $35 million to date with top payouts reaching $2 million. Meta also reported $4 million in bounty rewards last year. For organizations and individuals tracking their own exposure surface, tools like an privacy checkup and an SSL/TLS checker can help identify misconfigurations that bounty-style researchers frequently target.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →