block #0008 in --:--:--Join the pool
PENDING…
ai pending 3/6 1h ago · 3 min read

OpenAI $300 bug bounty Sparks Fury Over Free Paid-Model Access

OpenAI $300 bug bounty row: a researcher says a sandbox escape let him use paid models with no API key, OpenAI paid $300, and he says he will stop reporting to them.

pending 3/6 — still in the mempool

Early story. Some claims here are not officially confirmed yet. We update this post as it confirms.

OpenAI $300 bug bounty Sparks Fury Over Free Paid-Model Access
tl;dr
  • Fish's report was titled "Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API," and a screenshot he shared shows a $300 award.
  • The flaw, as described, bypassed sandbox isolation and API authentication at the same time. There's no public proof of concept, CVE or fix date.
  • OpenAI hasn't commented publicly. This is a researcher claim reported by Cyber Security News on October 7, not a confirmed incident.
in this block
  1. What actually happened
  2. Why $300 set people off
  3. The other side of the argument
  4. What it means for API users
  5. How to read the OpenAI $300 bug bounty fight
  6. What to do as a reader

The OpenAI $300 bug bounty story is security Twitter's favorite rage-bait this week. Researcher Oliver Fish says he found an unauthenticated sandbox escape that reached an internal OpenAI Responses API route and let him use paid models with no API key and no account. OpenAI paid him $300, and he says he's done reporting bugs to them.

What actually happened

According to Cyberstack, which cites Cyber Security News, Fish says he escaped an OpenAI sandbox and sent requests to paid AI models without any credentials. If that's accurate, it skipped identity and billing checks completely: no login, no card and no rate limit tied to a real customer.

LLMBytes put it neatly: a metered product with nothing doing the metering. Fish shared a screenshot of the payout on X and added: "Zero reason to report anything else I find to them."

What we don't have matters as much. There's no public endpoint, no list of affected models, no exposure window, no fix note, and no public evidence that customer data was touched or that anyone else used the hole.

Why $300 set people off

OpenAI runs its bounty program on Bugcrowd and pays by severity. Cyberstack says the program ranges from $200 for low-severity bugs to $20,000 for exceptional ones. LLMBytes describes the top end as five figures and more. We're citing both instead of picking one.

Either way, $300 sits near the bottom. The award may reflect a lower internal severity rating, but OpenAI hasn't explained its reasoning. For a bug that reportedly handed out the product OpenAI bills for, many researchers read that as a lowball.

A bounty only works while reporting pays better than staying quiet.

That's the incentive problem. If labs underpay for bugs that hit their own revenue, the next finder might sell the bug, sit on it or abuse it quietly. The OpenAI $300 bug bounty became shorthand for that fear.

The other side of the argument

Bounty programs score severity on impact, not headlines. If the route was rate-limited internally, fixed quickly, or exposed only limited model access, OpenAI's triage team may have rated it low on purpose. We don't know, because the company hasn't said.

Researchers also sometimes overstate impact in public posts, and screenshots don't prove scope. Until either side publishes details, the fairest read is a disputed payout on an unverified scope.

What it means for API users

Cyberstack notes there's nothing for customers to patch. The suggested hygiene is simple: keep usage alerts and spending limits on OpenAI API projects, and review usage logs for anything you didn't run.

If you run your own model gateway, the lesson is broader. Enforce authentication at every internal hop and block anonymous model calls from sandboxes. Plenty of AI products now give code-execution sandboxes to users, and each one is a possible path to internal services.

This also fits a pattern we've tracked. Our PixelLeak coverage showed how AI agent tooling can leak data in unexpected places, and the OpenAI Decisions API launch added yet another endpoint family to secure.

How to read the OpenAI $300 bug bounty fight

Treat it as a governance story more than a breach story. The claim, if true, is serious, but the evidence is one researcher's post and a payout screenshot. The real question is whether OpenAI will explain its severity call or raise its rewards.

Watch for an OpenAI statement, a technical write-up from Fish, or a change to the program's reward table. Any of those would turn this from vibes into something you can verify.

What to do as a reader

If you build on OpenAI, set hard spending caps today and enable usage alerts, whatever happens with this story. Check your own sandboxes and internal routes for missing auth checks.

If you're a researcher, read the OpenAI Bugcrowd program terms before you dig, so you know how severity is scored. For wider OpenAI context, see our report on OpenAI safety resignations. Nothing here is investment advice.

Not financial advice. DYOR, ser.

More in the pool

all ai
gm ser

Get confirmed before the crowd

Daily block at 07:00 UTC. No spam, just the block, ser.