Microsoft Corporation Pays Record $20 Million in Security Bounty Rewards
Microsoft Corporation paid 562 security researchers $20 million for vulnerability reports between June 2025 and July 2026, a record increase driven partly by AI tools.
Microsoft Corporation paid a record $20 million in bounty rewards to 562 security researchers across 64 countries from June 2025 through July 2026. This total marks an increase from the $17 million paid during the previous year. The company attributed the rise in vulnerability reports in 2026 partly to researchers using artificial intelligence in their security work.
These payments were managed through the Microsoft Bounty Program to encourage coordinated vulnerability disclosure. The reward cycle coincided with the July Patch Tuesday rollout, which addressed 570 vulnerabilities. Microsoft Corporation noted that only two of those vulnerabilities were being actively exploited by attackers when the patches were released.
As part of its security efforts, the company also hosted the Zero Day Quest live hacking event at its Redmond campus. Researchers at the event earned $2.3 million for submitting 700 reports.