Researcher Gets $300 from OpenAI for Major AI Security Flaw OpenAI paid security researcher Oliver Fish $300 through its Bugcrowd program for reporting a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to OpenAI's paid models and internal Responses API. Fish called the payout too low, saying it gives him "zero reason to report anything else I find to them," and the security community criticized the amount as an insult for a severity-10 issue, comparing it to Meta's bounties of up to $300,000. $300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them. Researcher Gets $300 from OpenAI for Major AI Security Flaw Last updated Oct 7, 2026 Fish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure. This story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs. Related Trending Stories on X Understand that this is a sev 10 exploited vulnerability, the highest an org will ever see. Reasonable bounties on something like this is in the mid-to-high 4 figures, or into 5 figures. This is an insult. ❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes. bugbounty.meta.com/payout-guideli… https://bugbounty.meta.com/payout-guidelines/muse/ Muse bugs pay up to $300k, attack us instead $300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them. ❗️ OpenAI awarded a researcher just $300 for a sandbox escape that gave free access to its paid models, with no API key and no account. "Zero reason to report anything else I find to them," researcher Oliver Fish concludes. these are so ridiculous unlimited token workaround should give you at least $3m $300 for a bug that gives free access to OpenAI’s paid models with no API key or account. Zero reason to report anything else I find to them.