Facebook has awarded a security researcher $20,000 for discovering a vulnerability in the Facebook Login SDK. The vulnerability is a cross-site scripting (XSS) flaw in the window.postMessage() method of the platform s code. Facebook has had a bug-bounty program in place since 2011. The highest bounty that Facebook has paid to date has been $50,000, to a researcher who identified a bug in the developer subscription mechanism that could allow for a misuse in notifications on certain types of user activity.
Source: https://threatpost.com/login-facebook-bug-20k-bounty/155732/

