Microsoft distributed over $20 million across 2,531 eligible reports to 562 security researchers in 64 countries between July 1, 2025, and June 30, 2026. That surpassed the previous year’s $17 million payout to 344 researchers, according to Microsoft.
The surge was fueled by an expansion of eligible targets, including open-source dependencies and third-party code, including a dramatic second-half increase in reports driven by artificial intelligence. Live hacking initiatives like Zero Day Quest added $2.3 million to the total, with the largest single reward reaching $200,000.
Addressing the global effort, Microsoft emphasized the collaborative nature of its program: “Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers.”
Friction in the hunter community
Despite record overall payouts, structural strain is emerging within the researcher ecosystem. Average earnings per participant dropped from $49,000 in the previous period to approximately $35,000.
Simultaneously, researcher relations faced high-profile friction. A bug hunter operating as Nightmare Eclipse publicly released zero-day exploits outside coordinated disclosure, alleging that Microsoft mishandled reports and withheld bounty payments. The dispute highlighted the risks vendors face when relationships with independent security researchers deteriorate.
Protecting silicon and hardware IP
None of this year’s coverage mentioned semiconductors, but it’s worth watching. As Microsoft’s bounty programs now reward flaws in third-party and open-source components tied to its cloud infrastructure, that net could eventually catch firmware and driver-level vulnerabilities sitting closer to the silicon; the kind of bugs that matter most for chip security and hardware IP protection.
AI-assisted bug hunting is already fast enough to comb through massive codebases; extending that scrutiny toward hardware-adjacent software would be a logical next step, especially as cloud providers race to secure the custom AI chips increasingly running their data centers.
Rebalancing bounties in the automated era
The arrival of AI-assisted vulnerability scanning alters the unit economics of security defense. While AI democratizes bug hunting by lowering entry barriers, it also risks flooding triage teams with high-volume, lower-complexity reports—which helps explain why average per-researcher earnings fell even as total corporate spending set records.
For enterprise leaders and technology vendors, record bounty spending demonstrates that relying primarily on reactive bug rewards is insufficient. To maintain defense-in-depth, organizations must shift bounty incentives toward deep system architecture flaws and hardware-level isolation rather than surface-level bugs that automated AI scrapers can easily detect.
Other News: Microsoft warned that a Russian state-backed hacking group is compromising legitimate hotel Wi-Fi portals to trick travelers into installing malware that can steal credentials and give attackers remote access to their devices.





