OpenAI launched its bug bounty program in April 2023 with payouts of up to $20,000 for researchers who report vulnerabilities, bugs, or security flaws in its product line via the Bugcrowd crowdsourced security platform. Artificial intelligence company OpenAI has announced a fivefold increase in the maximum bug bounty rewards for "exceptional and differentiated" critical security vulnerabilities from $20,000 to $100,000. For instance, until April 30, OpenAI has doubled payouts for security researchers who report Insecure Direct Object Reference (IDOR) vulnerabilities in its infrastructure and products, with a maximum reward of $13000. OpenAI unveiled its bug bounty program one month after disclosing a ChatGPT payment data leak blamed on a bug in its platform's Redis client open-source library. The company says that model safety issues are out of scope, just as jailbreaks and safety bypasses exploited by ChatGPT users to trick the chatbot into ignoring safeguards implemented by OpenAI engineers. As disclosed then, this bug caused the ChatGPT service to expose chat queries and personal data (subscriber names, email addresses, payment addresses, and partial credit card information) for roughly 1.2% of ChatGPT Plus subscribers. "We are significantly increasing the maximum bounty payout for exceptional and differentiated critical findings to $100,000 (previously $20,000)," the company said.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Fri, 28 Mar 2025 17:55:06 +0000