# Researcher Gets $300 from OpenAI for Major AI Security Flaw

> Source: <https://x.com/i/trending/2107776361859293195>
> Published: 2026-10-08 06:01:05+00:00

$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. 
Zero reason to report anything else I find to them.

# Researcher Gets $300 from OpenAI for Major AI Security Flaw

Last updated Oct 7, 2026

Fish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure.

This story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs.

## Related Trending Stories on X

Understand that this is a sev 10 exploited vulnerability, the highest an org will ever see. Reasonable bounties on something like this is in the mid-to-high 4 figures, or into 5 figures.
This is an insult.

❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account.
"Zero reason to report anything else I find to them," researcher Oliver Fish concludes.

[bugbounty.meta.com/payout-guideli…](https://bugbounty.meta.com/payout-guidelines/muse/)Muse bugs pay up to $300k, attack us instead!

$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. 
Zero reason to report anything else I find to them.

❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account.
"Zero reason to report anything else I find to them," researcher Oliver Fish concludes.

these are so ridiculous unlimited token workaround should give you at least $3m

$300 for a bug that gives free access to OpenAI’s paid models with no API key or account. 
Zero reason to report anything else I find to them.
