AI helps Microsoft bug hunters chase a record $20M payday
Microsoft has revealed that it paid out a record $20 million in bug bounties to 562 researchers between July 2025 and June 2026, up from around $17 million paid to 344 researchers the previous year. The surge reflects both an expanded bounty policy and a rapid rise in AI-assisted vulnerability research, which Microsoft says is reshaping how bugs are found and reported, both by outside researchers and its own security teams.
Microsoft attributed the increase partly to a December 2025 policy change making critical vulnerabilities "in scope by default" even when the flaw lay in third-party or open-source code affecting its online services, worth $800,000 in otherwise-ineligible rewards, plus $2.3 million awarded through its Zero Day Quest event. The company also linked its recent run of unusually large Patch Tuesday releases, including a record 622 vulnerabilities in July, to growing use of AI in vulnerability discovery. Separately, Microsoft has faced disruption from a researcher known as NightmareEclipse, who claims mistreatment by the company led them to publish serious zero-days, including privilege escalation and BitLocker bypass flaws, outside coordinated disclosure.
- Microsoft paid $20M in bug bounties to 562 researchers in 2025-26.
- Broader "in scope by default" rules and AI-assisted research drove the rise.
- July also saw a record 622 vulnerabilities patched in one month.