None
EN
Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges
['Aminu Abdullahi']
eSecurity Planet
Microsoft distributed over $20 million across 2,531 eligible reports to 562 security researchers in 64 countries between July 1, 2025, and June 30, 2026.
That surpassed the previous year’s $17 million payout to 344 researchers, according to Microsoft.
A bug hunter operating as Nightmare Eclipse publicly released zero-day exploits outside coordinated disclosure, alleging that Microsoft mishandled reports and withheld bounty payments.
The dispute highlighted the risks vendors face when relationships with independent security researchers deteriorate.
For enterprise leaders and technology vendors, record bounty spending demonstrates that relying primarily on reactive bug rewards is insufficient.