Updates & announcements related to Meta Bug Bounty program.
If you have found a security vulnerability, we encourage you to let us know ⬇️bugbounty.meta.comJoined March 2023
Why we built it: the context that makes a Meta request make sense — what an opaque ID refers to, which GraphQL operation actually runs — isn't visible from outside. So we brought our tooling to where you already work.
bugbounty.meta.com/blog/zurp-open…
Zurp is now open source. 🧰
Meta Bug Bounty's research toolkit, inside the proxy you already have open. Meta context, CSRF token handling and FBDL access. Every capability is available to your AI agents too.
github.com/facebookincuba…
🚀 FBDL just went agentic!
We released an open-source MCP server for Facebook Bug Description Language — Meta's tool for building security test environments programmatically.
Tell your AI agent: "I need two users who are friends, one owns a page, the other comments on a post and gets blocked" and it builds everything for you.
No browser, no manual FBDL.
This started as a community project by researcher Ads Dawson at our 2026 Meta Bug Bounty Researcher Conference. We collaborated to extend it with API integration and full run lifecycle support.
Open source. Built with researchers, for researchers.
🔗 bugbounty.meta.com/blog/fbdl-goes…#BugBounty#SecurityResearch#AI#MCP#Meta#MBBRC26
MBBRC has ended! 🎉
Thank you to every researcher who joined us. The submission window is still open — submit your reports by May 29.
Results will be announced after the deadline. Stay tuned.
#BugBounty#MetaSecurity#MBBRC
🇳🇵 From Nepal to the World 🌍
Excited to be in Taipei, Taiwan 🇹🇼 for Meta Bug Bounty Researchers Conference 2026 alongside 82 top security researchers from 25 countries.
Proud to represent Nepal on the global stage 🇳🇵
#meta#bugbounty#mbbrc2026#bountycon#cybersecurity
Just got back from the Meta Bug Bounty Researcher Conference in Taiwan 🇹🇼
Spent the week hacking @Meta AI and submitted 24 vulnerability reports
The best part wasn’t the bugs, it was collaborating with some seriously talented hackers and close friends: Ads Dawson, @Ph1R3574R73r, Edward Morris, and @wunderwuzzi23 from BT6.
Huge thanks to the @Metabugbounty team for hosting an incredible event and creating space for researchers to push on real AI security issues.
AI security is moving fast. Prompt injection, agent abuse, data exfiltration, unsafe tool use, the attack surface is real, and we’re just getting started.
🔒 One week to go! Meta Bug Bounty Researchers Conference 2026 is heading to Taipei, Taiwan 🇹🇼
82 top security researchers from 25 countries. Live hacking. Real impact.
May 6–9 → bugbounty.meta.com/events/#BugBounty#MetaSecurity#MBBRC2026
We’re teaming up with @PortSwigger to support the security community and help researchers find and report real-world issues faster.
Learn more about the Meta Bug Bounty x PortSwigger collaboration: bugbounty.meta.com/blog/meta-bug-…
Excited to announce that Manus is now in scope for the Meta Bug Bounty program. 🎯
Check the Manus scope here: bugbounty.meta.com/en-gb/scope/
Thanks for all your contributions — looking forward to your findings and submissions!
📢 Meta Bug Bounty Researcher Conference 2026
📍 Taipei, Taiwan
📅 May 6–9
Bringing together security researchers worldwide to connect, learn, and collaborate.
Details coming soon on bugbounty.meta.com/events 🔐
#BugBounty#MBBRC2026#InfoSec