Microsoft has paid a record $20 million to ethical hackers through its Bug Bounty Program. This the biggest payout since the initiative began. The AI giant said that from July 1, 2025, to June 30, 2026, it awarded $20 million to 562 security researchers, roughly $35,000 per person.
One of the biggest drivers was the Microsoft Zero Day Quest, where Microsoft welcomed ethical hackers and researchers to its Redmond campus. It resulted in approximately 700 vulnerability reports and $2.3 million in awards. According to reports, the challenge brought researchers together from 20 countries. Hackers focused on high-priority security scenarios across Microsoft’s cloud and AI platforms.
Another driver was the event where the tech giant asked researchers to find bugs in open-source software, third-party components, and Microsoft cloud services. It resulted in over 300 additional reports and more than $800,000 in payouts for vulnerabilities that were previously uncovered.
Also Read: Microsoft Stock Jumps After Q4 Earnings Beat as Azure Revenue Tops $100B
Notably, in 2025, the challenge was spread across 59 countries, which was increased to 64 countries this year. The $17 million payout was also distributed among 344 researchers. So, each of them received around $49,000. However, this year, the per-person payment was reduced significantly.
Cyberattacks are becoming more common, and no company can find every security flaw on its own. That is why many major technology firms now work with ethical hackers instead of treating them as outsiders. Their findings often help companies release security updates much faster. As hackers become more sophisticated, partnerships with ethical researchers will remain one of the strongest ways to keep software secure.