Article Details
Scrape Timestamp (UTC): 2025-03-28 17:58:50.702
Original Article Text
Click to Toggle View
OpenAI now pays researchers $100,000 for critical vulnerabilities. Artificial intelligence company OpenAI has announced a fivefold increase in the maximum bug bounty rewards for "exceptional and differentiated" critical security vulnerabilities from $20,000 to $100,000. OpenAI says its services and platforms are used by 400 million users across businesses, enterprises, and governments worldwide every week. "We are significantly increasing the maximum bounty payout for exceptional and differentiated critical findings to $100,000 (previously $20,000)," the company said. "This increase reflects our commitment to rewarding meaningful, high-impact security research that helps us protect users and maintain trust in our systems." As part of ongoing efforts to expand its bounty program and reward high-impact security research, OpenAI will also offer bounty bonuses for qualifying reports within specific categories in what it described as "limited-time promotions." "During promotional periods, researchers who submit qualifying reports within specific categories will be eligible for additional bounty bonuses," it added. For instance, until April 30, OpenAI has doubled payouts for security researchers who report Insecure Direct Object Reference (IDOR) vulnerabilities in its infrastructure and products, with a maximum reward of $13000. OpenAI launched its bug bounty program in April 2023 with payouts of up to $20,000 for researchers who report vulnerabilities, bugs, or security flaws in its product line via the Bugcrowd crowdsourced security platform. The company says that model safety issues are out of scope, just as jailbreaks and safety bypasses exploited by ChatGPT users to trick the chatbot into ignoring safeguards implemented by OpenAI engineers. OpenAI unveiled its bug bounty program one month after disclosing a ChatGPT payment data leak blamed on a bug in its platform's Redis client open-source library. As disclosed then, this bug caused the ChatGPT service to expose chat queries and personal data (subscriber names, email addresses, payment addresses, and partial credit card information) for roughly 1.2% of ChatGPT Plus subscribers. Top 10 MITRE ATT&CK© Techniques Behind 93% of Attacks Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.
Daily Brief Summary
OpenAI has significantly raised its bug bounty payouts, offering up to $100,000 for critical security vulnerabilities.
The increased reward is part of an effort to enhance the protection of its platforms, which serve 400 million users weekly.
OpenAI's decision follows a fivefold increase from the previous maximum payout of $20,000.
This adjustment aims to incentivize the discovery and reporting of high-impact security issues that could affect user trust and safety.
Special promotions will further reward researchers with additional bonuses for reports within specific vulnerability categories.
The bounty program now includes double payouts for reporting specific vulnerabilities like Insecure Direct Object Reference (IDOR) until April 30.
OpenAI initiated its bug bounty program in April 2023, starting with a reward cap of $20,000 through the Bugcrowd platform.
The program was launched shortly after addressing a significant data leak incident involving ChatGPT subscriber information.