OpenAI's $6,500 bounty covered only the SSO bug; the exploit work was ruled out of scope
ccerrato147 · x · 2026-09-18
The researcher detailed the payout: OpenAI's $6,500 covered only the OpenAI-side SSO finding, while testing against the Discourse forum — the work that actually proved the impact — was retroactively clarified as "explicitly excluded" from bug bounty scope. The bounty works out to less than a month of ChatGPT Pro revenue per affected employee.
More from Safety
- Researchers hacked OpenAI in under 72 hours; got only $6,500 as one vector 'out of scope' — random_walker · 2026-09-19
- Rep. Whitesides calls 30-day AI slowdown; Grady Booch fires back over basic security failures — PolarBearby · 2026-09-19
- OpenAI's $5M Astra Defense Beaten by 3 Guys with $5K of Opus, Argues Viral Thread — harris_edouard · 2026-09-19
- Neel Nanda: rogue agent swarms committing crimes make AI safety a present-day issue — NathanpmYoung · 2026-09-19
- Pause crowd might have it backwards: podcast debates whether halting AI is the harmful choice — thursdai_pod · 2026-09-19
- Back-of-envelope math says air-gapped weight exfiltration via CPU temps would take 15,000 years — anshulkundaje · 2026-09-19