OpenAI Boosts Bug Bounty to $100,000 for Critical Security Flaws


# OpenAI Boosts Bug Bounty Rewards to $100,000 for Critical Vulnerabilities

OpenAI has significantly increased its maximum bug bounty rewards from $20,000 to $100,000 for researchers who discover “exceptional and differentiated” critical security vulnerabilities. This fivefold increase reflects the company’s commitment to protecting its platforms, which serve approximately 400 million users across businesses, enterprises, and governments worldwide each week.

“This increase reflects our commitment to rewarding meaningful, high-impact security research that helps us protect users and maintain trust in our systems,” the company stated.

## Limited-Time Promotions

As part of its expanded bounty program, OpenAI will offer additional bonuses for qualifying reports within specific categories during promotional periods. For example, until April 30, the company has doubled payouts for researchers who report Insecure Direct Object Reference (IDOR) vulnerabilities, with rewards reaching up to $13,000.

## Program Background

OpenAI launched its bug bounty program in April 2023 via the Bugcrowd crowdsourced security platform. The program specifically excludes model safety issues, jailbreaks, and safety bypasses that ChatGPT users might exploit to circumvent safeguards.

The bug bounty program was established one month after OpenAI disclosed a ChatGPT payment data leak caused by a bug in its Redis client open-source library. This incident exposed chat queries and personal data for approximately 1.2% of ChatGPT Plus subscribers, including names, email addresses, payment addresses, and partial credit card information.

Share This Article