---
title: 5 Things Just Revealed by Facebook's Whitehat Program  
description: Facebook just reported on its bug bounty program for 2017. Here are the top 5 revealing facts about its work with whitehat hacker$.
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# [5 Things Just Revealed by Facebook's Whitehat Program  ](https://www.secureworld.io/industry-news/fast-facts-facebook-bug-bounty-whitehat-program)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Mon | Jan 15, 2018 | 3:41 PM Z

Securing a social media platform with a billion-plus users takes more than an InfoSec team.

It takes an army of whitehat hackers who uncover cybersecurity vulnerabilities, document them, and then share that information with the company in exchange for a reward.

Facebook just revealed highlights of its bug bounty program, showing both how it played out and how it *paid out* in 2017.

### **5 facts from Facebook's bug bounty, whitehat hacking program**

- *How much did Facebook pay in bug bounties in 2017?* A cool $880,000
- *What is the average bug bounty paid by Facebook in 2017?* $1,900, which is up significantly from $1,675 the prior year
- *How many apparent security vulnerabilities were submitted to Facebook in 2017?* A little more than 12,000
- *Whitehats from which countries submitted the most flaws to Facebook's bug bounty program?* In order: 
    - India
    - United States
    - Trinidad-Tobago (maybe they were inspired by the [tropical views](https://www.google.com/search?q=trinidad+tobago&source=lnms&tbm=isch&sa=X&ved=0ahUKEwiOw-a9otrYAhUS6WMKHU2-AvsQ_AUIDCgD&biw=1514&bih=708)?)
- * Which whitehat hackers are being publicly thanked *by* Facebook's bug bounty program for 2017?* You can [see the list here](https://www.facebook.com/whitehat/thanks/)—maybe you recognize some of them by their screen name or Twitter handle.

And Facebook says in 2018 it's going to offer faster payment and recognition for valid cybersecurity vulnerability reports, along with the chance to get free swag and invites to special events. If you want to get on board that gravy train, here is how you can submit a report: [https://www.facebook.com/whitehat/resources](https://www.facebook.com/whitehat/resources)

With more companies adding bug bounty programs themselves or through vendors, it looks like 2018 will be another profitable year to be a security researcher.

[View full post](https://www.secureworld.io/industry-news/fast-facts-facebook-bug-bounty-whitehat-program)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2018-01-15T20:03:48.404Z",
  "datePublished" : "2018-01-15T15:41:27Z",
  "headline" : "5 Things Just Revealed by Facebook's Whitehat Program  ",
  "image" : {
    "@type" : "ImageObject",
    "height" : 168,
    "url" : "https://cdn2.hubspot.net/hubfs/2221756/Social%20Media%20images/Facebook_Privacy_-_Labeled_for_Reuse_1.jpg",
    "width" : 300
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/fast-facts-facebook-bug-bounty-whitehat-program",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```