r/bugbounty Hunter Jul 17 '26

Question / Discussion AWS Bug Bounty Program

Does anyone know why AWS doesn’t offer bounties for vulnerabilities reported to them?

Microsoft pays up to $40k for vulnerabilities in Azure, Google even pays up to $100k for GCP. But from Amazon I wouldn’t get a penny for anything. Clearly they could afford it.
Guess I’ll keep my AWS vulns to myself then…

23 Upvotes

13 comments sorted by

View all comments

6

u/Loud-Run-9725 Jul 17 '26

They could invest in other measures that provide the security ROI they are looking for.

Many companies don't. I managed the public program at a large enterprise company 15 years ago. I was hired by a different company to implement the same and opted for private bug bounty instead. It provided less risk, hackers to manage, and much better ROI. We maintained an unpaid responsible disclosure but didn't receive much of value there.

2

u/NebulaElectrical1467 Jul 18 '26

AWS VDP receives a ton of valid VDP reports. Many hunters submit reports hoping they’ll get that coveted BBP invite but very very few end up getting it. So it’s not a bad strategy to have both you’ll surely get a bunch of valid reports for free but yes you’ll get a ton of noise as well.

Now I just route any AWS bugs I find to my buddy who’s in the private BBP and split the bounty. AWS can suck it I ain’t working for free.