2024 payout numbers: what the program saw
Meta’s bug bounty program processed almost 10,000 submissions in 2024, paying out more than $2.3 million across nearly 600 valid reports. The year’s awards went to roughly 200 researchers in more than 45 countries, with India, Nepal, and the United States accounting for the largest shares. Since the program started in 2011, total bounties have now passed $20 million.
Expanding GenAI scope
Meta continued rolling out new generative AI products through 2024 and gave researchers a clearer view of what is in scope for LLM-related reports. The published scope now welcomes submissions that show integral privacy or security issues in Meta’s large language models, including evidence of training-data extraction via model inversion or extraction attacks. Early results have included several high-impact GenAI reports, and Meta plans to keep this area active as the product surface grows.
New payout guidance for ads audience and Quest research
Ads audience tools
For potential security bugs in Meta’s ads audience targeting tools, the company introduced dedicated payout guidelines to explain how report impact is assessed. If a report demonstrates exposure of PII (name, email, phone number, state, ZIP, or gender) tied to an ads audience, the maximum base payout is capped at $30,000. That base is then adjusted downward based on required user interaction, prerequisites, and other mitigating factors to reach a final award.
Quest and mixed reality hardware
Meta continued to steer researchers toward its mixed reality and AI-driven hardware. In 2024, bug bounty reports flagged potential Quest vulnerabilities affecting safety settings and leading to possible memory corruption. Meta also brought Quest 3 and Ray-Ban Meta glasses to hardwear.io USA 2024, where hardware researchers could test the devices and look for vulnerabilities.
Community work and milestones
The annual Meta Bug Bounty Researcher Conference (MBBRC) took place in Johannesburg with 60 top researchers from around the world. The event generated more than 100 bug reports and over $320,000 in awards. Meta also co-presented research findings at EkoParty, DEF CON, Hardwear.io, Pwn2Own, and other industry events.
Long-time contributor Philippe Harewood reached a 10-year milestone with more than 500 valid reports paid out. His notable work in that stretch includes research on an Instagram access token leak and a video capture limit bypass on Ray-Ban Stories.
Meta continues to use its bug bounty site as the central resource for program updates, with quick announcements also posted to the program’s Instagram, Facebook, and X accounts.
What’s next
The program is planning new initiatives while keeping its existing community and bringing in new researchers. Private bug bounty tracks will continue giving experienced researchers early access to unreleased features for testing. The 2025 MBBRC is scheduled for May 12–15 in Tokyo, with further details to follow.



