Google has announced a record-breaking year for its Vulnerability Reward Program (VRP). In 2025, the tech giant paid out more than $17 million to ethical hackers worldwide to help secure its platforms.
This major milestone marks a massive 40% increase compared to 2024 and perfectly aligns with the program’s 15th anniversary.
Over 700 security researchers across the globe received financial rewards for discovering and reporting critical vulnerabilities before malicious actors could exploit them.
One of the most significant changes in 2025 was Google’s heightened focus on artificial intelligence security.
Google launched a dedicated AI Vulnerability Reward Program to offer researchers clearer testing scopes and better reward guidelines.
Previously, AI vulnerabilities fell under the general Abuse VRP, but the technology’s rapid growth required a specialized approach.
Additionally, the Chrome browser VRP expanded its rules to include specific reward categories for security flaws discovered in AI features, such as Gemini integrations.
Google also invested heavily in live hacking events and open-source security tools throughout the year.
The company introduced a new patch reward program for OSV-SCALIBR, an open-source tool designed to find vulnerabilities in software dependencies.
Contributors who provided novel scanning plugins were rewarded, and these external submissions have already helped Google uncover and remediate leaked secrets internally.
On the community front, Google hosted multiple invite-only bugSWAT live hacking events globally, bringing top researchers together to hunt for high-impact bugs. Key event highlights included:
As cyber threats continue to evolve, Google remains committed to collaborating with the external security community.
In 2026, the company plans to host several more bugSWAT events and the next edition of its ESCAL8 cybersecurity conference.
By working closely with independent researchers and rewarding their efforts, Google aims to stay ahead of emerging threats and continuously strengthen the security of its global products and services.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Google has begun routing some organic Search result links through opaque google.com/goto?url=... redirects, reducing users’…
Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated…
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin…
Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited…
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could…
A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution…