Skip to content
by InfinyAI ES

IA en un minutoNewsSecurity

Security

OpenAI pays $300 for a flaw that, according to the researcher who found it, gave free access to its paid models

IA en un minuto newsroom · Editor: Jon Elgezabal

In 30 seconds

Security researcher Oliver Fish showed on X that OpenAI had granted $300 through Bugcrowd for a bug Fish discovered. With it, according to Fish, anyone could use OpenAI's paid models without paying, with no account or API key, by getting into its internal Responses API. Fish considers the sum inadequate, and OpenAI had not spoken publicly when Europa Press reported the story.

Security researcher Oliver Fish posted on X on Wednesday, October 7 the notice from OpenAI's bug bounty program, which runs on the Bugcrowd platform: $300 for a flaw that the report describes as an unauthenticated sandbox escape that gave access to OpenAI's internal Responses API. According to Fish, it allowed free use of the company's paid models, with no API key or account. In the screenshot Fish posted, one word of the report title is hidden with asterisks.

Bug bounty programs pay people who find a security flaw and report it privately, so that the company can fix it before anyone exploits it. In OpenAI's Bugcrowd program, according to Europa Press, the usual rewards range from $200 to $6,500 per vulnerability, and the company reserves the right to change the priority and the amount based on the likelihood or impact of the flaw. Europa Press reads the $300 payout as a sign that OpenAI rated the flaw as low severity.

Fish says the amount is too low for a flaw like this and that there is zero reason to report anything else found to OpenAI. The post has passed 17,000 likes on X. On Reddit, as reported by Europa Press, many users agree that the reward is low for a flaw that requires no authentication; some say exploiting it would have paid more, others point to the possible legal consequences of doing so, and several share similar experiences with flaws reported to Microsoft, Apple or Google.

Europa Press points to a similar case: in July 2025, according to 9to5Mac, researcher RenwaX23 received $1,000 from Apple for the Safari flaw CVE-2025-30466, already fixed in Safari 18.4, even though Apple rated it 9.8 out of 10 for severity and its program pays up to $2 million.

As of the Europa Press report on Thursday, October 8, OpenAI had not commented publicly on the researcher's criticism or on the payout.

Why it matters · analysis and opinion

A bug bounty program works as long as whoever finds a flaw has more to gain from reporting it privately than from publishing it or keeping it quiet. When a researcher who has just been paid announces publicly that there will be no more reports, the cost for the company is not the amount but the next flaws that nobody may tell it about. OpenAI has not explained publicly how it assessed this case, and without that explanation it is impossible to know whether the flaw was less serious than its discoverer says or whether the program pays too little. For any company that runs, or plans to set up, its own program, the case leaves a clear idea: the amount is also a message, and whoever finds a flaw looks at it before deciding whether to report.

Source: Europa Press · Written with the help of AI: how we make the news

Is your website up to scratch? We will audit it for free

AI in your inbox, every day or every Friday

The stories that matter, each one in a minute. With the source for every one.

Choose one or both:

You will get an email to confirm your subscription: until you click its link, you will not receive anything. You can unsubscribe from any email.