In what year did Facebook launch its bug bounty program?

The story behind the answer

Facebook launched its bug bounty program in 2011. The company announced the program on July 29, 2011, promising security researchers at least $500 for responsibly reporting qualifying vulnerabilities on Facebook’s website.

The program formalized a relationship between Facebook and independent researchers who could discover security flaws before attackers exploited them. Instead of publicly revealing a vulnerability immediately, researchers could submit details to Facebook so its security teams could investigate and repair the issue.

Bug bounty programs became an important part of modern web security because even large engineering teams cannot test every possible interaction in a complex platform. Facebook’s program helped encourage ethical, coordinated disclosure and made security research a recognized contribution rather than automatically treating every researcher as an attacker.

The original program focused on security holes in Facebook’s website. Over time, Facebook expanded its security efforts to cover more products and vulnerability types. The launch year is sometimes confused with later increases in reward amounts or the creation of related security initiatives, but the founding announcement dates to 2011.

Source: Wikipedia · fact-checked Aug. 2026

Add question to a list

Choose a list to keep this question in: