Β© ROOT-NATION.com - Use of content is permitted with a backlink.
Microsoft announced that this yearβs Bug Bounty program paid out the largest amount in the programβs history. According to the company, between July 1, 2025, and June 30, 2026, $20 million was paid out to 562 security researchers. On average, this amounts to about $35,000 per participant. One of the factors contributing to this result was the Microsoft Zero Day Quest research competition, which took place at the Microsoft campus in Redmond. During the event, participants searched for vulnerabilities in real time, and during this period, the tech giant received nearly 700 vulnerability reports, with total rewards reaching $2.3 million.
Read also: AERONAUT β everything that flies above the ground: aviation, UAVs and drones, rockets, and space
Microsoft noted that Zero Day Quest brought together researchers from 20 countries. Participants focused on priority security scenarios related to Microsoftβs cloud platforms and AI solutions.

Another factor driving the increase in payouts was the expansion of the list of areas where security researchers can search for vulnerabilities. This year, Microsoft went beyond traditional areas to include open-source software, third-party components, and cloud services. This resulted in over 300 additional reports and more than $800,000 in payouts for vulnerabilities that were not previously covered by the program.
Read also:Β Everything You Need to Know About Moonshot AI’s Kimi K3: How Chinese Startup Challenged AI Giants
This year, reports of discovered vulnerabilities came from researchers in 64 countries, compared to 59 last year. Last year, the company paid out $17 million to 344 researchers, averaging $49,000 per person β a record at the time. At the same time, despite the higher total amount of payouts this year, the average reward per participant has decreased significantly.

Read also:Β How to Make an AI Explainer Video: A 7-Step Workflow
The company also noted that in the second half of the reporting period, from January to June 2026, the number of reports submitted increased noticeably due to more active community participation and the wider use of AI in security research.
The impact of AI on the field of security research is quite interesting. On the one hand, it allows more people to get involved in this field and receive rewards for discovered vulnerabilities. On the other hand, it forces companies to revise their programs so that more attention is paid to critical and particularly dangerous vulnerabilities. GitHub recently adjusted its reward tiers, and Apple has limited, by default, the number of vulnerability reports researchers can submit.
Read also:Β A Massive Failure: 58,000 Students Will Be Forced to Retake Their Exams Due to an AI Scandal




