Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsGoogle’s bugSWAT live-hacking event at ESCAL8 generated a reported $458,000 in rewards, according to a November 12, 2025, SecurityWeek report. Google’s later review put the Mexico City event’s rewards at $566,000 “to date,” while confirming the same 107 reports. The figures reflect different reporting points; neither source provides a payment ledger explaining the increase.
How much did Google pay at the live hacking event?
SecurityWeek reported $458,000 in payouts for bugSWAT at ESCAL8 in New Mexico on November 12, 2025. Google’s subsequent review of 2025 reported $566,000 in rewards to date for the ESCAL8 Mexico City edition. The later figure is cumulative as of Google’s review, rather than evidence that the earlier report was incorrect. The sources establish the difference in timing, but do not detail when individual rewards were validated or paid.
Google’s official account describes the Mexico City event and says it generated 107 reports, totaling $566,000 in rewards to date: Google Security Blog’s 2025 review.
What was bugSWAT at ESCAL8?
bugSWAT is an invite-only, live-hacking event within Google’s Vulnerability Reward Program (VRP). At ESCAL8, invited researchers tested targets across AI, Android, and Google Cloud over three days. The format combined hands-on vulnerability hunting with training and knowledge exchange.
#1 Best Overall
SecurityWeek’s contemporaneous account said 38 bug hunters took part and submitted 107 reports during the event: SecurityWeek’s November 2025 report.
How many researchers and reports were involved?
- 38 bug hunters participated, according to SecurityWeek’s event report.
- 107 reports were submitted over three days, according to SecurityWeek; Google’s later review also gives 107 reports for the Mexico City edition.
- The tested areas included AI, Android, and Google Cloud.
A report is not necessarily the same as a unique confirmed vulnerability: the cited accounts give the number of reports but do not say how many were accepted as distinct security issues.
How did ESCAL8 support the wider security community?
ESCAL8’s program extended beyond the live-hacking sessions. It included init.g(mexico), HACKCELER8 and its CTF final, a Safer with Google seminar, and an introductory cybersecurity workshop. Google’s event recap says more than 60 local university students attended sessions covering offensive security, web security, and cryptography.
Google’s event recap describes the activities and student workshop: Google’s ESCAL8 Mexico recap.
How does ESCAL8 fit Google’s 2025 bug-bounty program?
Google says its VRP awarded more than $17 million in 2025. Its annual-review graphic lists 747 paid researchers and $81.6 million awarded since the program began in 2010. Those program-wide figures provide context for bugSWAT, but they are not totals for ESCAL8.
The same review names other live-hacking editions: AI bugSWAT Tokyo generated more than $400,000 for 70+ reports, Cloud bugSWAT Sunnyvale generated $1.6 million for 130 reports, and Las Vegas generated $380,000 for 77 reports. These are separate events and should not be combined with ESCAL8’s payout or report count.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

