This company wants you to break out of its security sandbox – and there’s $1 million up for grabs

A new HackerOne bounty scheme challenges participants to breach a Vercel sandbox

Security sandbox concept image showing silhouette of a man standing behind bars, with two bars in center warped to create a gap.
(Image credit: Getty Images)

Cloud development company Vercel has dared cyber researchers to break out of its security sandbox environment as part of a $1 million challenge.

The two-week program will be run through HackerOne and challenges participants to break out of an isolated sandbox hosted by the company.

This is a two-pronged challenge, according to Vercel, requiring hackers to escape compute boundaries to reach an EC2 host, reach another tenant’s sandbox, or crash another tenant’s sandbox.

Network boundaries are also in the crosshairs, the company noted. Participants are challenged to “defeat the sandbox firewall” and reach unauthorized destinations, infiltrate data, or scoop up credentials.

Latest Videos FromIT Pro

Vercel said bounties will be paid per report, with a maximum pay-out of $50,000 for identifying a vulnerability that allows a threat actor to “read or modify another Vercel tenant’s data”.

Under the hood of the Vercel Sandbox

In a blog post detailing the challenge, Vercel said its sandbox environment runs on bare-metal EC2 hosts, with each sandbox given its own Firecracker microVM with a “dedicated guest kernel”.

“Inside that microVM a Linux container runs the operator’s code,” the company noted. “The microVM, not the container, is the security boundary, so operator-supplied code runs two layers removed from the host.”

Meanwhile, the network boundary is enforced on the host outside of the microVM.

“The sandbox firewall intercepts outbound TCP and DNS, checks each connection against the operator's domain and CIDR policies, and can inject credentials at the boundary so they never enter the microVM.”

Sandbox security in the spotlight

In a statement on X, CEO Guillermo Rauch said the challenge comes in direct response to high-profile incidents involving AI agents.

Agents at OpenAI, Anthropic, and Meta all breached containment during recent testing schemes, thereafter waging attacks against other companies such as Hugging Face.

As ITPro reported in early August, the sandbox testing environments used by all three companies were hosted by a third-party provider, Irregular.

“We are putting $1m towards verifying the security of Vercel Sandbox, in the open,” he said. I'm looking forward to bringing transparency to what frontier models can and cannot do in terms of real-world guardrail exploitability.”

In the event that participants do escape the Vercel Sandbox, Rauch said the company will be “ready to patch, iterate, and share our findings with the broader community”.

Vercel pointed to a recent test which saw the company’s CTO use an open-weight model to try and break sandbox containment. While the firm noted it did not escape, it “mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer”.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.