Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Meta paid external security researchers more than $2.3 million in bug bounties during calendar year 2024, according to the company’s February 13, 2025 retrospective. Meta said it received nearly 10,000 reports, awarded bounties for nearly 600 valid reports, and paid nearly 200 researchers across more than 45 countries.
The 2024 figures at a glance
| Metric | 2024 figure |
|---|---|
| Bounty awards | More than $2.3 million |
| Reports received | Nearly 10,000 |
| Valid reports receiving awards | Nearly 600 |
| Researchers paid | Nearly 200 |
| Countries represented | More than 45 |
| Top countries by bounty awards | India, Nepal and the United States |
| Cumulative payouts since 2011 | More than $20 million |
These are Meta’s figures and use approximate terms such as “nearly” and “more than.” The $2.3 million refers to bounty awards paid to external researchers—not Meta’s total security budget, which also includes employees, infrastructure, audits, incident response and remediation.
What the report numbers mean
Using the reported figures, roughly 600 awarded reports out of nearly 10,000 submissions works out to about 6%. That is a calculation, not Meta’s official acceptance or success rate. Submissions can be duplicates, out of scope, technically valid but ineligible for payment, or unable to demonstrate meaningful security impact.
Similarly, dividing the minimum reported payout by the approximate number of awarded reports suggests at least about $3,833 per awarded report. Dividing it by the approximate number of paid researchers suggests at least about $11,500 per researcher. Neither figure is a reported average: the actual distribution, median bounty and largest individual award were not disclosed.
#1 Best Overall
A broader security program in 2024
Meta’s program covered major services including Facebook, Messenger, Instagram, WhatsApp and Workplace, as well as newer products and technologies. The company’s current program overview lists Meta Quest, Ray-Ban hardware, Meta AI and open-source projects among its areas of coverage. Because program scope changes, the current page should not be treated as an exact historical snapshot of 2024.
Generative AI and large language models
Meta said it opened GenAI features to researchers through its bug-bounty program in 2023 and provided more detail in 2024 about qualifying LLM research. The company emphasized integral privacy or security issues, including possible extraction of protected training information through model inversion, model extraction or related attacks.
That distinction matters. A jailbreak, prompt-injection result, hallucination or undesirable response is not automatically a bounty-eligible vulnerability. The relevant question is whether the behavior creates a demonstrable security or privacy impact under Meta’s rules.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Advertising-audience tools
Meta also introduced payout guidance for vulnerabilities in tools used to select advertising audiences. It said exposure of specified personally identifiable information—such as a name, email address, phone number, state, ZIP code or gender—could have a maximum base payout of $30,000 before deductions.
That amount was a category maximum, not a guaranteed or typical payment. Deductions could reflect required user interaction, exploitation prerequisites and other mitigating factors.
Quest and mixed-reality hardware
Meta highlighted research involving Quest products and hardware-related issues that could affect safety settings or cause memory corruption. It also brought Quest 3 and Ray-Ban Meta glasses to Hardwear.io USA 2024 for hardware-security testing.
Rank #3
Potential payout ceilings
SecurityWeek’s report, citing Meta’s program guidelines, listed maximum potential rewards including:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Up to $300,000 for mobile vulnerabilities leading to code execution.
- Up to $145,000 for account-takeover vulnerabilities.
- Up to $45,000 for certain Meta hardware bugs.
- Up to $40,000 for server-side request forgery vulnerabilities.
- Up to $30,000 for certain advertising-audience privacy exposures.
These figures describe possible maximums or category amounts, not expected compensation. Meta evaluates impact, exploitability, prerequisites, user interaction, duplication, report quality and applicable bonuses or deductions. Its current overview also says listed amounts are shown without bonuses and that Hacker Plus and applicable bonuses can add up to 30% of the original bounty; that later program information should not automatically be applied to every 2024 award.
The researcher community
Meta said its 2024 Meta Bug Bounty Researcher Conference in Johannesburg brought together 60 leading researchers. The event generated more than 100 reports and more than $320,000 in awards. Those figures describe a subset of the wider program and should not be added to the annual total unless Meta explicitly identifies them as separate.
Rank #4
Meta also highlighted researcher Philippe Harewood, who reached a 10-year milestone and had more than 500 valid reports paid by the program.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How 2024 compares with earlier years
Meta reported more than $2 million in bounty payments in 2022, with around 10,000 reports and more than 750 reports receiving bounties. In 2021, it said it had awarded more than $2.3 million at that point in the year, received around 25,000 reports and paid bounties on more than 800 reports. In 2020, Meta said it awarded more than $1.98 million.
Recommended Free Tools
These comparisons provide context but not a precise year-over-year trend. Meta’s scope, reporting periods, terminology and counting methods may differ. The lower number of paid reports reported for 2024 does not prove that individual rewards increased.
Best Value
What makes a useful submission?
Meta’s report-writing guidance emphasizes detail and reproducibility. A strong report generally includes:
- A concise vulnerability title.
- The affected product, endpoint, feature or asset.
- A clear explanation of security or privacy impact.
- Precise reproduction steps.
- A proof of concept that minimizes access to real users’ data.
- Required accounts, permissions and prerequisites.
- Supporting request/response samples, screenshots or logs.
- A possible remediation direction, where appropriate.
This checklist does not guarantee payment. Researchers must follow Meta’s current scope, terms and testing rules. Testing involving personal data should minimize access, collection and retention; hardware work may also require specialized devices, firmware versions, physical access and safety precautions.
What the $2.3 million does not prove
- It is not Meta’s total investment in security.
- It does not show the median, average or largest bounty.
- It does not reveal the severity distribution of findings.
- It does not establish how quickly reports were triaged or fixed.
- It does not show how many vulnerabilities were exploited before discovery.
- It does not prove that Meta’s products became safer by a specific measurable amount.
- It is not evidence that the conference awards were additional to the annual total.
The clearest conclusion is that Meta’s external-security program remained large and strategically broad in 2024. Its spending reached beyond traditional web and mobile applications into AI, advertising privacy, virtual-reality devices and smart glasses. That makes the total meaningful as a measure of the program’s scale—not as a standalone measure of Meta’s overall security performance.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

