Security researchers blast OpenAI's "nightmarish" vulnerability disclosure process

evilsocket · x · 2026-09-19

Security researcher @S1r1u5 says the $6,500 bounty wasn't even the issue in their recent OpenAI bug dispute — the disclosure process itself was. They describe it as nightmarish, requiring lawyers and ultimately escalation to a journalist, calling it "one of the worst disclosure processes." LiveOverflow published a thread dissecting how OpenAI's CISO fumbled the situation (his personal opinion). The episode highlights growing friction between the security research community and OpenAI's vulnerability handling.

Original post →

More from Safety

Safety channel →