Facebook has paid out a whopping $2m since it introduced its bug bounty program in 2011. The company received 14,763 submissions from researchers in 2013, a year on year increase of 246%. The majority of the flaws submitted during that year proved to be invalid, leaving some 687 that were eligible to receive an award. The largest number of bugs (136) were discovered by residents of India, with the average payout totalling $1,353. A Brazilian, Reginaldo Silva, received Facebooks largest ever bounty payment of $33,500 (about 20,000) and a job.”]
Source: https://nakedsecurity.sophos.com/2014/04/04/facebook-bug-bounty-program-paid-out-1-5m-in-2013/

