$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.
Last updated Oct 7, 2026
Fish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure.
This story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs.
Related Trending Stories on X #
Understand that this is a sev 10 exploited vulnerability, the highest an org will ever see. Reasonable bounties on something like this is in the mid-to-high 4 figures, or into 5 figures. This is an insult.
❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes.
bugbounty.meta.com/payout-guideli…Muse bugs pay up to $300k, attack us instead! $300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.
❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes.
these are so ridiculous unlimited token workaround should give you at least $3m
$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.