Microsoft recently revealed that it has distributed over $20 million in rewards through its bug bounty programs in the past year, marking a significant milestone in its ongoing cybersecurity efforts. The program, which spans multiple initiatives, received contributions from researchers in 64 different countries.
Significant Contributions from Global Researchers
From July 1, 2025, to June 30, 2026, Microsoft accepted 2,531 valid vulnerability reports, with 562 researchers earning a share of the bounty. The largest individual reward reached an impressive $200,000, reflecting the critical nature of some of the reported vulnerabilities.
Key to these efforts was the Zero Day Quest hacking contest, where participants collectively received $2.3 million. Additionally, new programs focusing on vulnerabilities in third-party and open source software distributed $800,000.
Rising Engagement and AI’s Role
The latter part of the year saw a surge in submissions, spurred by robust engagement from the cybersecurity community and the increasing use of artificial intelligence in security research. This uptick highlights the evolving landscape of cybersecurity where AI plays a pivotal role.
In comparison, Microsoft allocated approximately $17 million to bug bounty payouts in 2024 and 2025, and around $13 million annually between 2020 and 2023, illustrating a steady increase in both participation and rewards over time.
Challenges and Criticisms
Despite the program’s success, not all researchers are satisfied. An individual known online as Chaotic Eclipse has criticized Microsoft for its handling of vulnerability reports, claiming that the company failed to address certain issues adequately. This includes allegations of ignored communications and withheld payments, which led to the public disclosure of unpatched vulnerabilities.
These criticisms underscore the challenges tech companies face in maintaining effective and transparent bug bounty programs, which are crucial for safeguarding digital ecosystems.
As Microsoft continues to refine its approach, the importance of collaboration with the research community remains paramount. With new technologies and threats emerging, ongoing engagement and adaptation will be essential to the success of such initiatives.
