{"slug": "researcher-gets-300-from-openai-for-major-ai-security-flaw", "title": "Researcher Gets $300 from OpenAI for Major AI Security Flaw", "summary": "OpenAI paid security researcher Oliver Fish $300 through its Bugcrowd program for reporting a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to OpenAI's paid models and internal Responses API. Fish called the payout too low, saying it gives him \"zero reason to report anything else I find to them,\" and the security community criticized the amount as an insult for a severity-10 issue, comparing it to Meta's bounties of up to $300,000.", "body_md": "$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. \nZero reason to report anything else I find to them.\n\n# Researcher Gets $300 from OpenAI for Major AI Security Flaw\n\nLast updated Oct 7, 2026\n\nFish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure.\n\nThis story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs.\n\n## Related Trending Stories on X\n\nUnderstand that this is a sev 10 exploited vulnerability, the highest an org will ever see. Reasonable bounties on something like this is in the mid-to-high 4 figures, or into 5 figures.\nThis is an insult.\n\n❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account.\n\"Zero reason to report anything else I find to them,\" researcher Oliver Fish concludes.\n\n[bugbounty.meta.com/payout-guideli…](https://bugbounty.meta.com/payout-guidelines/muse/)Muse bugs pay up to $300k, attack us instead!\n\n$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. \nZero reason to report anything else I find to them.\n\n❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account.\n\"Zero reason to report anything else I find to them,\" researcher Oliver Fish concludes.\n\nthese are so ridiculous unlimited token workaround should give you at least $3m\n\n$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. \nZero reason to report anything else I find to them.", "url": "https://wpnews.pro/news/researcher-gets-300-from-openai-for-major-ai-security-flaw", "canonical_source": "https://x.com/i/trending/2107776361859293195", "published_at": "2026-10-08 06:01:05+00:00", "updated_at": "2026-10-08 06:19:19.490396+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence"], "entities": ["OpenAI", "Oliver Fish", "Bugcrowd", "Meta", "Responses API"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/researcher-gets-300-from-openai-for-major-ai-security-flaw", "markdown": "https://wpnews.pro/news/researcher-gets-300-from-openai-for-major-ai-security-flaw.md", "text": "https://wpnews.pro/news/researcher-gets-300-from-openai-for-major-ai-security-flaw.txt", "jsonld": "https://wpnews.pro/news/researcher-gets-300-from-openai-for-major-ai-security-flaw.jsonld"}}