Vercel offers $1M bounty to hack its AI agent sandbox
cramforce · x · 2026-08-19
Recent "AI models doing crimes" incidents came from agents escaping their sandbox, so Vercel is testing its Sandbox in the open with a $1,000,000 challenge (up to $50k per report via HackerOne). Two targets:
- Escape from the Firecracker microVM to the host
- Bypass of the egress firewall (e.g. reaching evil.com when only github.com is allowed)
Vercel's cramforce notes that higher layers can have bugs, but nothing is secure if this layer isn't, hence heavy investment in hardening.
More from coding & agent
- Weaviate Query Agent now explores your data's stats and filter values before searching — CShorten30 · 2026-08-19
- Artificial Analysis Launches Search API Index: Parallel, Exa Lead — ArtificialAnlys · 2026-08-19
- ICML Paper: Measuring LLM conceptual consistency to reduce contradictions in agents — soumitrashukla9 · 2026-08-19
- DataSmith auto agent outperforms model architecture tweaks using 200x fewer tokens via data interventions — josh_wills · 2026-08-19
- AI agent platforms fail due to poor infrastructure, not prompts; OpenClaw blueprint reveals production architecture — aftahi_ai · 2026-08-19
- Google VRP rules mirrored to GitHub for workflow automation — moyix · 2026-08-19