• 2 min read
Microsoft pays record $20 million in bug bounties
Microsoft paid a record $20 million to 562 security researchers, as AI fuels more vulnerability reports and faster exploitation.

Image: Windows Central
Microsoft paid a record $20 million to security researchers through its Microsoft Bounty Program, as AI-assisted vulnerability discovery drives a surge in reports.
The rewards went to 562 researchers across 64 countries, up from $17 million paid to 344 researchers the previous year. Microsoft said the increase in submissions was partly linked to the growing use of AI by security researchers — and warned that attackers are also using AI to exploit vulnerabilities faster.
“Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers.”
Microsoft bounty payouts and expanded scope
Maximum rewards vary by the affected product and vulnerability type:
- Cloud programs and Zero Day Quest: up to $100,000 per vulnerability
- Endpoint and on-premises programs: up to $250,000 per vulnerability
- Copilot experience vulnerabilities: up to $30,000 per report
Those are ceilings rather than standard payments; Microsoft said many reports receive smaller awards. The company also expanded the program last year to include vulnerabilities in open-source software, third-party components, and Microsoft cloud services, in addition to its traditional bounty categories.
The program covers security issues across Microsoft’s cloud services, AI systems, enterprise platforms, and consumer technologies. Microsoft’s own AI systems are used to find and fix vulnerabilities, creating what the company describes as an arms race between attackers and defenders.

Recommended reading
AI cyber guardrails fall for simple authorization claims
Zero Day Quest generated 700 reports
Microsoft also highlighted the results of its Zero Day Quest event, which brought researchers from 20 countries to the company’s campus in Redmond, Washington. More than 700 vulnerability reports were filed, resulting in over $2.3 million in awards.
The new record shows Microsoft is putting substantially more money into external vulnerability research than before. That increase is not simply a larger budget: the program now covers more of the software supply chain, while AI is helping both researchers find flaws and attackers turn them into working exploits.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via Windows Central


