Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Microsoft paid $16.6 million to security researchers during its Microsoft Bounty Program year from July 1, 2023, through June 30, 2024. The company said 343 researchers in 55 countries helped identify more than 1,000 potential security issues. The figure was announced on August 5, 2024, and is historical—not Microsoft’s latest published annual total.
Microsoft subsequently reported $17 million distributed in its next published review, so “$16.6 million in the past year” should not be read as a current 2026 figure.
What the $16.6 million figure covers
Microsoft’s annual review covered rewards issued across its bounty programs during the July 1, 2023–June 30, 2024 program year. The company paid 343 researchers located in 55 countries. Microsoft said researchers identified more than 1,000 potential security issues; SecurityWeek reported that Microsoft received more than 1,300 eligible vulnerability reports during the period.
| Measure | Reported result |
|---|---|
| Program year | July 1, 2023–June 30, 2024 |
| Total rewards | $16.6 million |
| Researchers rewarded | 343 |
| Countries represented | 55 |
| Potential issues identified | More than 1,000, according to Microsoft |
| Eligible reports | More than 1,300, according to SecurityWeek |
| Largest individual reward | $200,000, as reported by SecurityWeek |
Microsoft’s announcement is available in its 2024 program review. The report count and $200,000 maximum were reported by SecurityWeek.
#1 Best Overall
Was this actually an increase?
Yes, compared with the roughly $13 million per year that SecurityWeek said Microsoft paid from 2020 through 2023. Against a $13 million baseline, $16.6 million is approximately 27.7% higher.
That comparison is directional rather than an audited, identical year-over-year accounting series. It also describes total program spending, not a 27.7% increase for every researcher or every type of vulnerability. Microsoft has not published a universal bounty rate that rose by that percentage.
Why Microsoft’s payouts rose
Microsoft broadened both the number of programs and the attack surfaces it wanted researchers to examine. During the 2023–2024 year, the company highlighted several changes:
- Launch of the Microsoft AI Bounty Program.
- Expansion of the Microsoft Identity Bounty Program to include authenticator applications.
- Expansion of the Microsoft 365 Insider program.
- Launch of the Microsoft Defender Bounty Program.
- A Dataverse Integrations Research Grant.
- A limited-time Windows Secure Boot bounty.
- Additional Microsoft 365 scenarios involving security-feature bypasses and other high-impact outcomes.
These initiatives focused incentives on cloud services, identity, artificial intelligence, endpoint defense and high-impact security failures. Microsoft did not assign a specific dollar amount to each change, so it is not possible to say how much of the $16.6 million came from any individual program. Broader scope and targeted rewards are the clearest documented reasons the total could rise.
Recommended Free Tools
Which Microsoft products are covered?
Microsoft operates separate programs with their own targets and rules. Areas represented in its bounty portfolio include:
- Azure and other cloud services
- Microsoft 365
- Windows
- Microsoft Edge
- Dynamics 365
- Power Platform
- Microsoft Defender
- Identity services and authenticator applications
- Xbox
- Artificial-intelligence services and related programs
This list does not mean every Microsoft product, configuration or third-party component is automatically eligible. Researchers must check the live Microsoft bounty-program directory for the applicable scope, exclusions, reward range and submission process. Scope can change after an article or older program page was published.
How Microsoft decides what to pay
There is no single Microsoft-wide bounty amount. Each program sets its own award ranges and eligibility rules. Microsoft says evaluations consider:
- Severity and realistic security impact
- Completeness and accuracy of the report
- Reproducibility of the result
- Whether the finding affects a high-priority security area
- The product-specific program rules and coordinated-disclosure requirements
A report that is technically interesting but cannot demonstrate a practical impact may receive less, or no, reward. Conversely, a reproducible issue that compromises a high-value security boundary can qualify for a substantially larger payment.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What the totals do—and do not—tell you
They are not an average bounty
Dividing $16.6 million by 343 rewarded researchers produces a simple arithmetic ratio of about $48,400 per researcher. That is not an official average: researchers submitted different numbers of reports, and the public total may include grants and different reward categories.
Rank #4
Dividing $16.6 million by more than 1,300 eligible reports produces less than approximately $12,800 per report. This denominator is imprecise because the report count is stated as “more than 1,300,” and an eligible report is not necessarily a paid report. Neither calculation represents a typical Microsoft payout or a guaranteed return for a new researcher.
They do not measure Microsoft’s security quality by themselves
A larger payout total can mean more researchers found reportable issues, more high-impact findings qualified for rewards, or that Microsoft expanded its programs. It does not, by itself, prove that Microsoft’s products became less secure or that a particular number of vulnerabilities existed in production.
The public figures do not show the median payment, the distribution by severity, the percentage of reports that earned money, the number of unique vulnerabilities paid, or the amount spent by each program.
Best Value
What researchers should check before testing
- Confirm the target. Verify that the product, tenant, endpoint or integration appears in the relevant Microsoft program scope.
- Read the rules of engagement. Check permitted techniques, rate limits, account requirements, data-handling rules and safe-harbor terms.
- Establish real impact. Explain the security boundary crossed and the attacker capabilities required; avoid relying on a purely theoretical scenario.
- Use a minimal proof of concept. Demonstrate the issue without accessing unnecessary data, disrupting service or affecting other users.
- Make reproduction straightforward. Include versions, configuration details, steps, logs and remediation-relevant evidence.
- Check for duplicates and exclusions. A previously known issue, unsupported version, out-of-scope target or third-party defect outside the program’s terms may not qualify.
- Submit through Microsoft’s process. Follow the program’s coordinated vulnerability disclosure instructions rather than publishing details immediately.
Following these steps improves triage quality but cannot guarantee payment. A large annual program total is an aggregate across many researchers, severity levels, grants and products—not a promise that an individual submission will receive a large award.
How coordinated disclosure fits the program
Microsoft uses coordinated vulnerability disclosure: a researcher privately reports a suspected issue, Microsoft investigates and remediates it, and disclosure is coordinated rather than immediate. A bounty is therefore not permission to test any Microsoft system in any manner.
Testing must remain within the relevant scope and rules, including restrictions on service disruption, personal-data handling and unauthorized access. Microsoft’s program directory is the controlling source for current requirements.
The next published year reached $17 million
In its next year-in-review, dated August 5, 2025, Microsoft said it distributed $17 million to 344 researchers from 59 countries and identified more than 1,000 potential vulnerabilities. That update puts the $16.6 million result in context: it was a significant 2023–2024 total, but not the endpoint of Microsoft’s published bounty spending.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Microsoft’s follow-up announcement is available at Microsoft’s 2025 year-in-review. Secondary reports in 2026 have described totals above $20 million, but without the underlying Microsoft announcement those figures should be treated as reported rather than independently verified.
Status of the $16.6 million headline
Status: The $16.6 million figure is accurate for Microsoft’s July 1, 2023–June 30, 2024 bounty-program year. Microsoft later reported $17 million for the following published year. Anyone seeking a current 2026 total should rely on the latest primary announcement from Microsoft’s Security Response Center, not on the older “past year” wording.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




