OpenAI to pay up to $20k in rewards through new bug bounty program
The move follows a period of unrest over data security concerns
OpenAI has unveiled a new bug bounty program offering rewards for security researchers if they can uncover vulnerabilities in its products.
In an announcement on Tuesday, the California-based AI firm said the bug bounty scheme is “essential to our commitment to develop safe and advanced AI” and deliver services that are secure, reliable, and trustworthy.
As part of the initiative, OpenAI said it will offer a tiered reward system based on the severity of bugs uncovered by researchers.
Rewards can range from as little as $200 for low-severity flaws with a maximum reward of $20,000 for “exceptional discoveries”.
“The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure,” the firm said in a statement.
“We invite you to report vulnerabilities, bugs, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone.”
Researchers participating in the new initiative will be able to disclose vulnerabilities or flaws through a partner organisation, Bugcrowd.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Bugcrowd will manage the submission and reward process, which OpenAI said is designed to “ensure a streamlined experience for all participants”.
ChatGPT vulnerability concerns
The move from OpenAI follows a period of unrest over security-related issues at the generative AI firm, which has close ties with Microsoft.
Last month, the company revealed that a bug in ChatGPT led to a leak of users' data.
RELATED RESOURCE
SOC modernisation and the role of XDR
How to cope with increasing threats and IT sprawl
This flaw meant that ChatGPT Plus users began seeing user email addresses, subscriber names, payment addresses, and limited credit card information.
The issue prompted the company to temporarily take the chatbot offline to work on a fix.
“The bug was discovered in the Redis client open-source library, redis-py,” OpenAI explained in a post at the time.
“As soon as we identified the bug, we reached out to the Redis maintainers with a patch to resolve the issue.”
Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
From tokenmaxxing to valuemaxxingIn-depth AI needs to be integrated into broader financial planning if firms want to move forward with a strategy that delivers sustainable value
-
The managed service category nobody's named. Yet.Industry Insights MSPs have a narrow window to set the rules for agent governance
-
‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mindNews The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul
-
OpenAI has paused work on its Astra AI model after it passed a 'critical threshold' in cyber capability – but it’s not the one that breached Hugging FaceNews The firm said it's Astra model can "develop functional zero-day exploits of all severity levels"
-
Cyber criminals are selling discount AI tokens on underground forumsNews Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access
-
‘I bought the tool to save time, but I did more manual work than before’: Pentesters are finding more bugs with AI than they can fixNews Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads
-
Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attackNews The AI library chief has called for investment to help “build powerful cyber defenses”, as alleged weaknesses in OpenAI’s monitoring emerge
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely