Microsoft Bug Bounty Program Pays Record $20M, Fueled by AI and Expanded Scope
Microsoft's bug bounty program awarded a record $20 million to 562 researchers in its latest fiscal year, driven by AI advancements and a broader scope including third-party and open-source code.

Microsoft has announced a record-breaking year for its bug bounty program, disbursing over $20 million to 562 security researchers between July 1, 2025, and June 30, 2026. This figure surpasses the previous year's payout of approximately $17 million to 344 researchers, marking a significant increase in both rewards and the number of participating individuals.
The substantial rise in payouts is attributed to several key factors, including an expansion of the program's scope. In December 2025, Microsoft adopted an "In Scope By Default" policy, making critical vulnerabilities eligible for rewards even if they resided in third-party or open-source code that directly impacted Microsoft's online services. This strategic shift opened the door to a wider array of potential bug reports and subsequent payouts, contributing an estimated $800,000 in rewards that would not have been previously considered.
Further boosting the program's success was the "Zero Day Quest," Microsoft's security research challenge and live hacking event, which alone accounted for an additional $2.3 million in awards. The company also noted a surge in submissions during the latter half of the bounty year, a trend it partially attributes to the increasing adoption of artificial intelligence tools by external researchers to aid in their security investigations.
Internally, Microsoft is also leveraging AI to accelerate its vulnerability discovery efforts, which has contributed to the increasingly dense Patch Tuesday releases. The July 2026 Patch Tuesday, for instance, delivered a record 622 vulnerabilities, dwarfing the previous record of 206 set just a month prior. This trend of escalating vulnerability disclosures has been ongoing, with June and April also setting new records.
Microsoft's Executive Vice President of Windows + Devices, Pavan Davuluri, acknowledged the growing impact of AI on vulnerability research, both from external hunters and internal discovery tools. While highlighting the company's automated patching solutions to manage the influx of updates, the narrative around AI-driven vulnerability discovery suggests a new era of cybersecurity challenges and responses.
Adding a layer of complexity to the year's program was the emergence of a prolific researcher known as "NightmareEclipse." This individual, reportedly possessing deep knowledge of Microsoft's software, began disclosing zero-day vulnerabilities outside of coordinated disclosure channels, often shortly after Patch Tuesday. The researcher cited negative experiences with Microsoft's reporting process, including alleged insults and humiliation, as motivation for their actions, aiming to inflict "maximum pain" on the company.
Microsoft's response to NightmareEclipse included threats of involving its Digital Crimes Unit, signaling a willingness to engage law enforcement. This approach, however, reportedly exacerbated the situation, with some speculating that the researcher's actions may have inspired other aggrieved individuals to also bypass responsible disclosure protocols.
The confluence of AI-driven research, expanded program scope, and high-profile researcher disputes paints a dynamic picture of Microsoft's ongoing efforts to secure its vast ecosystem, highlighting both the opportunities and challenges presented by modern cybersecurity landscapes.