cd /news/ai-safety/researcher-gets-300-from-openai-for-… · home › topics › ai-safety › article
[ARTICLE · art-147387] src=x.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Researcher Gets $300 from OpenAI for Major AI Security Flaw

OpenAI paid security researcher Oliver Fish $300 through its Bugcrowd program for reporting a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to OpenAI's paid models and internal Responses API. Fish called the payout too low, saying it gives him "zero reason to report anything else I find to them," and the security community criticized the amount as an insult for a severity-10 issue, comparing it to Meta's bounties of up to $300,000.

by read2 min views1 publishedOct 8, 2026
Researcher Gets $300 from OpenAI for Major AI Security Flaw
Image: source

$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.

Last updated Oct 7, 2026

Fish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure.

This story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs.

Understand that this is a sev 10 exploited vulnerability, the highest an org will ever see. Reasonable bounties on something like this is in the mid-to-high 4 figures, or into 5 figures. This is an insult.

❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes.

bugbounty.meta.com/payout-guideli…Muse bugs pay up to $300k, attack us instead! $300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.

❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes.

these are so ridiculous unlimited token workaround should give you at least $3m

$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/researcher-gets-300-…] indexed:0 read:2min 2026-10-08 · —