Researcher breaks down OpenAI's DNS sandbox escape: a well-known trick, not novel

ns123abc · x · 2026-09-26

Security researcher S1r1u5 explains that OpenAI's DNS sandbox escape was essentially dig TXT queries to ch.at, a publicly documented LLM-over-DNS service. He argues the bug was neither novel nor hard to prevent — it resembles captive-portal bypass tricks — noting his team had reported a similar sandbox egress bypass variant before.

Original post →

More from Safety

Safety channel →