Google has announced a record-breaking year for its Vulnerability Reward Program (VRP). In 2025, the tech giant paid out more than $17 million to ethical hackers worldwide to help secure its platforms.
This major milestone marks a massive 40% increase compared to 2024 and perfectly aligns with the program’s 15th anniversary.

Over 700 security researchers across the globe received financial rewards for discovering and reporting critical vulnerabilities before malicious actors could exploit them.
One of the most significant changes in 2025 was Google’s heightened focus on artificial intelligence security.
Google launched a dedicated AI Vulnerability Reward Program to offer researchers clearer testing scopes and better reward guidelines.
Previously, AI vulnerabilities fell under the general Abuse VRP, but the technology’s rapid growth required a specialized approach.
Additionally, the Chrome browser VRP expanded its rules to include specific reward categories for security flaws discovered in AI features, such as Gemini integrations.
Live Hacking and Open Source Security
Google also invested heavily in live hacking events and open-source security tools throughout the year.
The company introduced a new patch reward program for OSV-SCALIBR, an open-source tool designed to find vulnerabilities in software dependencies.
Contributors who provided novel scanning plugins were rewarded, and these external submissions have already helped Google uncover and remediate leaked secrets internally.
On the community front, Google hosted multiple invite-only bugSWAT live hacking events globally, bringing top researchers together to hunt for high-impact bugs. Key event highlights included:
- Tokyo AI bugSWAT in April generated over 70 reports, resulting in more than $400,000 in rewards.
- Sunnyvale Cloud bugSWAT in June led to 130 reports, paying out an impressive $1.6 million to participants.
- Las Vegas bugSWAT in August secured 77 reports, issuing $380,000 to security researchers.
- Mexico City bugSWAT focused on AI, Android, and Cloud targets, generating 107 reports and $566,000 in payouts.
As cyber threats continue to evolve, Google remains committed to collaborating with the external security community.
In 2026, the company plans to host several more bugSWAT events and the next edition of its ESCAL8 cybersecurity conference.
By working closely with independent researchers and rewarding their efforts, Google aims to stay ahead of emerging threats and continuously strengthen the security of its global products and services.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





