Meta unveils $4 million bounty program for WhatsApp security research

Markets 2025-11-20 10:23

Meta has expanded its bug bounty program for WhatsApp, announcing new incentives to improve security research on the messaging platform alongside a $4 million award to white hat hackers who discover vulnerabilities.

According to the tech company’s press statement released on Tuesday, WhatsApp is a lucrative target for state-sponsored hackers and commercial spyware developers. Meta said the new initiative seeks to make it easier for security researchers to investigate hacking strategies used specifically on the app messenger.

Meta launches WhatsApp Research Proxy for bug bounty researchers

Meta has introduced a tool called the WhatsApp Research Proxy to help security researchers examine the messaging platform’s network protocol more effectively. Initially available to a select group of long-time bug bounty participants, the company said it helps simplify investigations into WhatsApp’s infrastructure.

The Research Proxy is intended to assist in uncovering vulnerabilities that might otherwise go undetected, and plans to expand access to more researchers over time are underway, leading to its public release in the coming months.

“Our goal is to lower the barrier of entry for academics and other researchers who might not be as familiar with bug bounties to join our program,” a Meta spokesperson said. “WhatsApp clients and server infrastructure are high targets but also among the hardest surfaces to find bugs in.”

Meta issues $25 million in payouts to global bug hunting participation

Meta confirmed that it has already paid $4 million this year for nearly 800 validated reports. Over the past 15 years, the company has awarded more than $25 million to 1,400 researchers from 88 countries, and it received approximately 13,000 submissions from security researchers worldwide.

According to the Facebook and Instagram parent company’s latest blog, academic researchers at the University of Vienna recently reported a novel method for enumerating WhatsApp accounts at scale. 

University of Vienna’s study generated lists of possible phone numbers using open-source tools, and checked if the numbers registered on WhatsApp compiled publicly accessible information. Although the research exceeded the platform’s intended limits, Meta said it provided valuable security flaws it needed to mitigate.

Other bugs were found in an incomplete validation flaw on WhatsApp versions prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83. 

The vulnerabilities could have allowed attackers to process content retrieved from arbitrary URLs on another user’s device. Meta released an operating system-level patch to address CVE-2025-59489, an exploit that could have installed malware on Quest devices to execute arbitrary code on Unity applications.

In its annual Bug Bounty Researcher Conference, security researcher RyotaK won the “Most Impact Award” for identifying bugs from the Quest device vulnerability traced to Unity’s third-party code. The researcher worked with Unity to resolve the issue affecting apps built on Unity 2017.1 and later.

Meta counts legal victory in antitrust US FTC case

Meta’s bug bounty program announcement comes on the heels of a legal win in its antitrust case against the US Federal Trade Commission, as reported by Cryptopolitan on Tuesday. 

The FTC had alleged five years ago that Meta held a monopoly in social networking through Instagram and WhatsApp. In a memorandum opinion, Judge James Boasberg of the US District Court in Washington, DC, said the FTC had failed to prove its case. 

“Whether or not Meta enjoyed monopoly power in the past, though, the agency must show that it continues to hold such power now. The Court’s verdict today determines that the FTC has not done so. A judgment so stating shall issue this day.”

Meta CEO Mark Zuckerberg, former operating chief Sheryl Sandberg, Instagram co-founder Kevin Systrom, and other executives all gave their testimonies earlier this year. The court had dismissed the case in 2021 for lack of evidence, although the FTC filed an amended complaint that year with updated metrics and user data. 

Boasberg allowed the case to proceed in 2022 after a review, but he finally ruled in Meta’s favor this week.

Joe Simonson, the FTC’s director of public affairs, argued that Meta was favored by Judge Boasberg, whom he claimed was “currently facing articles of impeachment.” 

“We are reviewing all our options,” Simonson told reporters after the ruling, insinuating that another appeal could come.

Join a premium crypto trading community free for 30 days - normally $100/mo.

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.