Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Meta Paid Out More Than $2.3 Million in Bug Bounties in 2024

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Meta paid external security researchers more than $2.3 million in bug bounties during calendar year 2024, according to the company’s February 13, 2025 retrospective. Meta said it received nearly 10,000 reports, awarded bounties for nearly 600 valid reports, and paid nearly 200 researchers across more than 45 countries.

The 2024 figures at a glance

Metric 2024 figure
Bounty awards More than $2.3 million
Reports received Nearly 10,000
Valid reports receiving awards Nearly 600
Researchers paid Nearly 200
Countries represented More than 45
Top countries by bounty awards India, Nepal and the United States
Cumulative payouts since 2011 More than $20 million

These are Meta’s figures and use approximate terms such as “nearly” and “more than.” The $2.3 million refers to bounty awards paid to external researchers—not Meta’s total security budget, which also includes employees, infrastructure, audits, incident response and remediation.

What the report numbers mean

Using the reported figures, roughly 600 awarded reports out of nearly 10,000 submissions works out to about 6%. That is a calculation, not Meta’s official acceptance or success rate. Submissions can be duplicates, out of scope, technically valid but ineligible for payment, or unable to demonstrate meaningful security impact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Similarly, dividing the minimum reported payout by the approximate number of awarded reports suggests at least about $3,833 per awarded report. Dividing it by the approximate number of paid researchers suggests at least about $11,500 per researcher. Neither figure is a reported average: the actual distribution, median bounty and largest individual award were not disclosed.

A broader security program in 2024

Meta’s program covered major services including Facebook, Messenger, Instagram, WhatsApp and Workplace, as well as newer products and technologies. The company’s current program overview lists Meta Quest, Ray-Ban hardware, Meta AI and open-source projects among its areas of coverage. Because program scope changes, the current page should not be treated as an exact historical snapshot of 2024.

Generative AI and large language models

Meta said it opened GenAI features to researchers through its bug-bounty program in 2023 and provided more detail in 2024 about qualifying LLM research. The company emphasized integral privacy or security issues, including possible extraction of protected training information through model inversion, model extraction or related attacks.

That distinction matters. A jailbreak, prompt-injection result, hallucination or undesirable response is not automatically a bounty-eligible vulnerability. The relevant question is whether the behavior creates a demonstrable security or privacy impact under Meta’s rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Advertising-audience tools

Meta also introduced payout guidance for vulnerabilities in tools used to select advertising audiences. It said exposure of specified personally identifiable information—such as a name, email address, phone number, state, ZIP code or gender—could have a maximum base payout of $30,000 before deductions.

That amount was a category maximum, not a guaranteed or typical payment. Deductions could reflect required user interaction, exploitation prerequisites and other mitigating factors.

Quest and mixed-reality hardware

Meta highlighted research involving Quest products and hardware-related issues that could affect safety settings or cause memory corruption. It also brought Quest 3 and Ray-Ban Meta glasses to Hardwear.io USA 2024 for hardware-security testing.

Potential payout ceilings

SecurityWeek’s report, citing Meta’s program guidelines, listed maximum potential rewards including:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Up to $300,000 for mobile vulnerabilities leading to code execution.
  • Up to $145,000 for account-takeover vulnerabilities.
  • Up to $45,000 for certain Meta hardware bugs.
  • Up to $40,000 for server-side request forgery vulnerabilities.
  • Up to $30,000 for certain advertising-audience privacy exposures.

These figures describe possible maximums or category amounts, not expected compensation. Meta evaluates impact, exploitability, prerequisites, user interaction, duplication, report quality and applicable bonuses or deductions. Its current overview also says listed amounts are shown without bonuses and that Hacker Plus and applicable bonuses can add up to 30% of the original bounty; that later program information should not automatically be applied to every 2024 award.

The researcher community

Meta said its 2024 Meta Bug Bounty Researcher Conference in Johannesburg brought together 60 leading researchers. The event generated more than 100 reports and more than $320,000 in awards. Those figures describe a subset of the wider program and should not be added to the annual total unless Meta explicitly identifies them as separate.

Meta also highlighted researcher Philippe Harewood, who reached a 10-year milestone and had more than 500 valid reports paid by the program.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How 2024 compares with earlier years

Meta reported more than $2 million in bounty payments in 2022, with around 10,000 reports and more than 750 reports receiving bounties. In 2021, it said it had awarded more than $2.3 million at that point in the year, received around 25,000 reports and paid bounties on more than 800 reports. In 2020, Meta said it awarded more than $1.98 million.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These comparisons provide context but not a precise year-over-year trend. Meta’s scope, reporting periods, terminology and counting methods may differ. The lower number of paid reports reported for 2024 does not prove that individual rewards increased.

What makes a useful submission?

Meta’s report-writing guidance emphasizes detail and reproducibility. A strong report generally includes:

  1. A concise vulnerability title.
  2. The affected product, endpoint, feature or asset.
  3. A clear explanation of security or privacy impact.
  4. Precise reproduction steps.
  5. A proof of concept that minimizes access to real users’ data.
  6. Required accounts, permissions and prerequisites.
  7. Supporting request/response samples, screenshots or logs.
  8. A possible remediation direction, where appropriate.

This checklist does not guarantee payment. Researchers must follow Meta’s current scope, terms and testing rules. Testing involving personal data should minimize access, collection and retention; hardware work may also require specialized devices, firmware versions, physical access and safety precautions.

What the $2.3 million does not prove

  • It is not Meta’s total investment in security.
  • It does not show the median, average or largest bounty.
  • It does not reveal the severity distribution of findings.
  • It does not establish how quickly reports were triaged or fixed.
  • It does not show how many vulnerabilities were exploited before discovery.
  • It does not prove that Meta’s products became safer by a specific measurable amount.
  • It is not evidence that the conference awards were additional to the annual total.

The clearest conclusion is that Meta’s external-security program remained large and strategically broad in 2024. Its spending reached beyond traditional web and mobile applications into AI, advertising privacy, virtual-reality devices and smart glasses. That makes the total meaningful as a measure of the program’s scale—not as a standalone measure of Meta’s overall security performance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.