Microsoft pays security researchers $20M following AI-backed surge in bug reports

Microsoft's Surface Pro 12-inch 1st Edition (2025) powered by Qualcomm Snapdragon X Plus processor.
A vulnerability report on the Copilot experience can result in an award of up to $30,000. (Image credit: Future | Daniel Rubino)

562 researchers across 64 countries were on the receiving end of $20 million of rewards from the Microsoft Bounty Program. That program has researchers work with Microsoft to identify and report vulnerabilities across Microsoft's products and services.

The program has been around for years, but the $20 million in awards is a new record. For context, the Microsoft Bounty Program awarded $17 million to 344 researchers last year.

How much researchers receive depends on the type of vulnerability they report. Cloud programs and Zero Day Quest vulnerabilities are capped at $100,000 per vulnerability. Reporting an Endpoint and On-Premises program vulnerability can be worth up to $250,000.

Latest Videos FromWindows Central

Of course, those are the maximum payouts per report. Many reported vulnerabilities result in smaller awards.

Microsoft expanded the scope of its researcher awards last year. Now, in addition to flagging traditional bounties, researchers can be rewarded for reporting vulnerabilities in open-source software, third-party components, and Microsoft cloud services.

Microsoft detailed the rewards in a recent blog post.

"Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers," said Microsoft. "The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies."

Microsoft credited the increase in submissions in part to AI. Increasingly, AI is being used to help security researchers.

Microsoft also uses AI to find and fix vulnerabilities as well. Unfortunately, AI can also be used by hackers to quickly leverage discovered vulnerabilities. As a result, there is an AI arms race happening between malicious actors and security researchers.

Microsoft also recalled the success of the Microsoft Zero Day Quest, which had researchers from 20 countries travel to Microsoft's campus in Redmond, Washington. Over 700 vulnerability reports were filed and over $2.3 million was awarded at that event.

Blank Pixel


Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.


Sean Endicott
News Writer

Sean Endicott is a News Writer at Windows Central, where he covers Windows 11, Surface hardware, Microsoft 365, AI, apps, and the broader PC ecosystem. Since joining the site in 2017, he has written well over a thousand articles across the Microsoft landscape, covering breaking news, analysis, and feature reporting.

He writes Windows Wrap, a weekly column covering the biggest stories in Windows and the PC industry, and what they mean for the platform going forward.

Before joining Windows Central full-time, Sean worked in journalism and media production after earning a First Class degree in Broadcast Journalism from Nottingham Trent University. Outside of tech, he is an award-winning American football coach based in Nottingham, England, and was named BAFCA Youth Coach of the Year in 2024.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.