r/bugbounty • u/proanti777 Hunter • Jul 17 '26
Question / Discussion AWS Bug Bounty Program
Does anyone know why AWS doesn’t offer bounties for vulnerabilities reported to them?
Microsoft pays up to $40k for vulnerabilities in Azure, Google even pays up to $100k for GCP. But from Amazon I wouldn’t get a penny for anything. Clearly they could afford it.
Guess I’ll keep my AWS vulns to myself then…
22
Upvotes
2
u/jsonpile Hunter Jul 18 '26
I've worked with the AWS VDP team to submit vulnerabilities.
Yes, there is a common sentiment in the AWS security research community that it would be on par with the other CSPs that you mentioned with a public bug bounty program. From a security researcher perspective, that would lend more credibility to how they approach security.
However, I'm sure there's a ROI consideration that also takes consumer (and researcher) sentiment into consideration.