TLDR: Microsoft has significantly increased the prize pool for its annual Zero Day Quest hacking contest to an unprecedented $5 million. This year’s challenge, running from August 4 to October 4, 2025, specifically targets critical security vulnerabilities within cloud computing and artificial intelligence platforms, reinforcing the company’s commitment to its Secure Future Initiative.
Redmond, WA – Microsoft has announced a substantial increase in the prize pool for its highly anticipated Zero Day Quest hacking contest, now offering up to $5 million in bounty awards. This move underscores the tech giant’s intensified focus on bolstering the security of its rapidly expanding cloud computing and artificial intelligence ecosystems. The company is touting this year’s event as the ‘largest hacking event in history,’ aiming to proactively identify and mitigate zero-day exploits before they can be weaponized.
The Zero Day Quest Research Challenge is set to run from August 4 to October 4, 2025, inviting security researchers globally to submit vulnerabilities. Participants stand to gain significantly, with Microsoft offering a +50% bounty multiplier for critical-severity vulnerabilities and high-impact scenarios discovered during this period. The targeted platforms include key Microsoft services such as Azure, Copilot, Dynamics 365, Power Platform, Microsoft 365, and Identity services.
Top-performing researchers from the challenge will earn an exclusive invitation to a live hacking event scheduled for Spring 2026 at Microsoft’s Redmond campus. This invite-only competition will foster direct collaboration between leading security researchers and Microsoft’s Security Response Center (MSRC) and product teams, aiming for a collaborative approach to enhance product resilience.
This initiative is a cornerstone of Microsoft’s broader Secure Future Initiative (SFI), an overhaul launched in late 2023 to improve its internal security posture following criticism from the U.S. Cyber Safety Review Board. SFI emphasizes ‘security by default and design’ and greater transparency in vulnerability management. Last year’s Zero Day Quest, which offered $4 million in rewards, saw significant participation, resulting in over 600 vulnerability submissions and $1.6 million paid out for groundbreaking research, particularly in Copilot AI and cloud services.
Also Read:
- Microsoft Unveils Project Ire: An Autonomous AI Agent for Advanced Malware Detection
- New AI Vulnerability ‘IdentityMesh’ Exposes Cross-System Exploitation Risks
To further support participants, Microsoft will offer training sessions from its AI Red Team, MSRC, and Dynamics teams, covering crucial areas like AI system testing, bug bounty programs, and advanced security research methodologies. By incentivizing ethical hacking and fostering collaboration, Microsoft aims to prevent major security incidents and ensure the integrity of its critical services in an evolving threat landscape.


