What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Apple said its Security Bounty program paid nearly $20 million to security researchers in its first two and a half years. That figure, announced October 27, 2022, is a historical milestone—not the program’s current lifetime total. Apple later reported awarding more than $35 million to more than 800 researchers since the public program launched in 2020.
How much has Apple paid out in bug bounties?
Apple’s October 2022 announcement put the program’s payments at nearly $20 million over its first two and a half years. In October 2025, Apple reported a later cumulative total: more than $35 million awarded to more than 800 researchers since the public program began in 2020. The totals are Apple’s own statements, not independently audited figures.
The later figure updates the historical $20 million headline, but neither announcement provides an award-by-award breakdown. Apple has not published a typical or median payout for the period, and the totals do not establish how many reports made up the earlier figure.
What is Apple’s maximum bug bounty?
As of October 7, 2026, Apple’s bounty page advertises rewards of up to $2 million for exploit chains comparable to sophisticated real-world attacks. Apple says bonuses can raise potential maximum rewards above $5 million. These are upper limits for qualifying findings, not standard payments or guaranteed awards.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Apple’s current categories page lists bonuses of 50% for qualifying beta-software issues, 100% for bypasses of specific Lockdown Mode protections, and 150% when both conditions apply. Some categories also require Target Flags. The category and its conditions determine what an eligible report may earn; the advertised maximum does not apply to every vulnerability.
What does a researcher need to qualify?
Apple’s guidelines make eligibility dependent on the quality, impact, and circumstances of a report. A submission generally needs to be the first complete and actionable report Apple receives, offer a reliable way to reproduce the issue, and describe an exploitable bug with potential real-world threat. Researchers must keep the issue confidential until Apple releases an update and security advisory.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For listed category rewards, Apple says the issue must affect the latest publicly available software and hardware with standard configurations. Target Flags are required where a category specifies them. Apple may still consider issues outside the listed categories if they significantly affect user security; low-impact issues that Apple fixes may qualify for $1,000.
Why Target Flags matter
Apple says Target Flags can help it objectively confirm exploitability. A qualifying report that uses them may receive accelerated award processing before a fix is available. This does not remove the confidentiality requirement: the researcher must still wait for Apple to release a fix before disclosing the issue.
Rank #3
- FIND YOUR ITEMS ON FIND MY — AirTag (2nd generation) helps you keep track of what matters. Attach one to an item you want to keep track of using the Find My app.*
- EXPANDED PRECISION FINDING ON IPHONE AND APPLE WATCH — Get step-by-step directions to your lost item on iPhone and, now, Apple Watch.*
- ENHANCED SPEAKER — With a 50% louder speaker and a new, distinctive chime, it’s easier than ever to hear and find AirTag.*
- PING FROM FAR AND WIDE — Upgraded Ultra Wideband and Bluetooth chips allow you to find your items from even farther away than ever before.*
- SHARE ITEM LOCATION — Share AirTag location access temporarily and securely with trusted contacts, third parties, or over 50 airline partners if you lose something important.
How quickly does Apple resolve reports?
Apple says most reports are resolved within 90 days. “Most” is not a guarantee for every report or award, and the stated timeframe does not establish when a particular researcher will be paid.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the payout totals do—and do not—show
- Historical total: Nearly $20 million was Apple’s reported payout for the program’s first two and a half years, announced October 27, 2022.
- Later cumulative total: Apple reported more than $35 million awarded to more than 800 researchers since the public program launched in 2020, announced October 10, 2025.
- Individual awards: Apple’s 2025 announcement said multiple individual reports earned $500,000 rewards, but it did not provide a full distribution of award sizes.
- Current ceiling: The current page advertises a $2 million top award and potential maximum rewards above $5 million with bonuses. Those figures concern qualifying findings under current rules, not the average researcher’s earnings.
Because the aggregate totals and maximum award measure different things, they should not be treated as a direct comparison of typical payouts. Apple’s published figures show program scale and possible high-end rewards, but they do not reveal what a typical accepted report earns.
Quick Recap
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.
Rank #4
- Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
- FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
- Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
- Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
- IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.
Apple sources
- Apple Security Research, “Apple Security Bounty. Upgraded.” (October 27, 2022)
- Apple Security Research, “A major evolution of Apple Security Bounty, with the industry’s top awards for the most advanced research” (October 10, 2025)
- Apple Security Bounty
- Apple Security Bounty Categories
- Apple Security Bounty Guidelines
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




