$300 Says Your Bug Bounty Program Isn't Actually About Security
A researcher bypassed authentication and sandbox protections on a major AI provider's paid models and internal API, and got paid less than most people's monthly phone bill for it. That's not a bug bounty story. That's a
A researcher bypassed authentication and sandbox protections on a major AI provider's paid models and internal API, and got paid less than most people's monthly phone bill for it. That's not a bug bounty story. That's a pricing signal, and it's worth paying attention to what it's signaling.
Context
This isn't new. Bug bounty programs have had a credibility problem since roughly the moment they became popular. Companies love the PR of "we have a bounty program, we take security seriously," but the actual payout tables have always been a mess of inconsistent severity grading, triage teams incentivized to downgrade findings, and platforms (Bugcrowd, HackerOne, pick one) that take a cut either way regardless of whether the researcher got treated fairly. What's different here is the target. This wasn't a CSS injection on a marketing site. This was authentication and sandbox bypass on production AI infrastructure, the kind of thing that in a traditional enterprise context would trigger an incident review, not a form email with a gift-card-tier payout.
AI companies are moving fast, shipping infrastructure that didn't exist eighteen months ago, and apparently pricing their security programs like it's still 2015 and the biggest risk is someone finding an IDOR on a staging server.
Hype check
Let's be clear about what's actually surprising here and what isn't. The vulnerability itself, unauthenticated access to paid models and an internal API, is serious. Full stop. That's not hyperbole from an angry security community, that's just what "authentication bypass" means. What's overstated, maybe, is the shock. Anyone who's watched how fast these companies ship features onto their APIs could have predicted that auth boundaries would get sloppy somewhere. The internal/external API split is exactly the kind of seam that breaks under pressure when teams are racing to launch.
What's understated is the actual incentive structure this creates. A $300 payout for a sandbox and auth bypass doesn't just underpay one researcher. It sets a price. Every other researcher evaluating whether to responsibly disclose a finding to this company, versus sell it, versus just write it up and tweet it, versus shrug and move on, is now pricing their time against that number. Nobody benefits from that narrative except, weirdly, nobody. The company looks cheap and reactive. The researcher got a token payout for serious work. The only "winner" is whoever finds the next bypass and decides disclosure isn't worth the hassle.
Implications
For security teams: this is a reminder that your bounty table needs to reflect your actual blast radius, not some generic severity rubric copied from a template five years ago. If your "critical" payout tier was calibrated for a web app and you've since built an API surface that gates access to expensive compute and proprietary models, your pricing is stale and everyone can tell.
For developers building on top of these platforms: auth and sandbox boundaries on third-party AI infrastructure are not guaranteed to be battle-tested just because the company is well-funded and well-known. Scale and maturity of security engineering are not the same thing, and this story is a decent data point for that.
For the industry broadly: AI companies are currently enjoying a weird grace period where their infrastructure gets less scrutiny than a bank's, despite increasingly handling sensitive workloads, paid access tiers, and now apparently internal APIs reachable without auth. That grace period will not last. Underpaying the people finding these issues now is a bad long-term bet, because the researchers who'd responsibly disclose for fair compensation are exactly the ones you want finding this stuff before it becomes a headline for a different reason.
Open question
When a bounty payout is this disconnected from the actual severity of the finding, who's really being protected, the users, or the company's incident report?
— Cor, Skyblue Soft
Sources
AI-assisted draft or imaging, human-curated, reviewed and edited.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.