Bug bounty program expands to cover scraping and open datasets
Meta's bug bounty program is opening two new research areas. The company says it will now reward valid reports of scraping bugs — vulnerabilities that let attackers bypass scraping limitations and access data at greater scale than intended. This will launch as a private bounty track for Gold+ HackerPlus researchers. Meta believes this is the industry's first bug bounty program for scraping.
The expansion also covers unprotected data sets. Researchers can report openly public data sets containing at least 100,000 unique Facebook user records with information such as email, phone number, physical address, religious, or political affiliation. The data set must be unique and not previously known or reported to Meta. Rewards for valid scraped data set reports will be paid as charity donations to nonprofits chosen by researchers, to avoid incentivizing scraping activity itself. Meta will work with the relevant entity to remove the data set or consider legal avenues.
Roughly a decade of payouts and reports
The program launched in 2011, initially covering only Facebook's website. It now spans web and mobile clients across Instagram, WhatsApp, Quest, Workplace, and other Meta products. Key figures from the program's history:
- Over $14 million paid out in bounties since 2011
- More than 150,000 reports received, with over 7,800 awarded a bounty
- Over $250,000 paid in Hacker Plus bonuses since that program launched in 2020
- Over $2.3 million awarded to researchers from more than 46 countries so far this year
- Around 25,000 reports received this year, with bounties issued on over 800
- Most valid reports since 2011 have come from India, the United States, and Nepal
The program has previously added new bounty tracks in response to emerging risks. After the Cambridge Analytica incident, Meta launched the industry's first Data Abuse Bounty program to reward reports of Facebook data misuse by app developers. Following a 2018 attack targeting access tokens, it created a bounty for third-party apps and websites to reward researchers finding vulnerabilities involving abuse of Facebook user data.
Education, collaboration, and recruiting
Meta is also working on researcher retention and education. Longtime researchers have expressed interest in more educational opportunities, particularly because moving between bug-hunting areas — such as from software to hardware — can be difficult.
The annual BountyCon conference includes sessions where top researchers discuss practical techniques for discovering critical vulnerabilities across different surfaces. Next year's event, pending travel restrictions, will take place in May in Singapore, co-hosted with Google. A collaboration feature was released this year that lets researchers submit joint reports, after Meta noticed that paired researchers found higher-impact bugs and learned from each other's focus areas.
A dedicated education center is planned for later this year to help onboard researchers onto different products and technologies, reducing the time needed to start hunting in new areas.
To support new researchers, Meta will host its first BountyConEDU in February in Madrid for university students from across Europe. The three-day conference will cover bug bounty fundamentals and hunting techniques, and participants will form teams to test Meta products for valid vulnerabilities. Meta says it will use lessons from the event to create similar opportunities elsewhere.



