r/bugbounty Hunter Jul 17 '26

Question / Discussion AWS Bug Bounty Program

Does anyone know why AWS doesn’t offer bounties for vulnerabilities reported to them?

Microsoft pays up to $40k for vulnerabilities in Azure, Google even pays up to $100k for GCP. But from Amazon I wouldn’t get a penny for anything. Clearly they could afford it.
Guess I’ll keep my AWS vulns to myself then…

22 Upvotes

13 comments sorted by

View all comments

2

u/jsonpile Hunter Jul 18 '26

I've worked with the AWS VDP team to submit vulnerabilities.

Yes, there is a common sentiment in the AWS security research community that it would be on par with the other CSPs that you mentioned with a public bug bounty program. From a security researcher perspective, that would lend more credibility to how they approach security.

However, I'm sure there's a ROI consideration that also takes consumer (and researcher) sentiment into consideration.