AI Pulse by Inblix

OpenAI supercharges bug bounty, now paying up to $100K

OpenAI Blog · Jul 14, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: OpenAI supercharges bug bounty, now paying up to $100K

OpenAI is betting that bigger payouts and a broader research scope will harden its defenses on what it calls the ambitious path toward AGI. The company announced a massive increase to its Security Bug Bounty Program, with maximum payouts for exceptional, critical findings jumping from $20,000 to $100,000. To sweeten the deal immediately, limited-time bonus promotions are launching for qualifying reports in specific categories, though researchers need to check the program page for exact eligibility windows.

The move to quintuple the top payout isn’t happening in a vacuum. It coincides with an evolution of the company’s two-year-old Cybersecurity Grant Program, which has already funded 28 projects from over a thousand applications. The program is now actively soliciting proposals in several priority areas: using AI to automatically detect and patch software vulnerabilities, improving model privacy to prevent training data leaks, and boosting the resilience of AI agents against sophisticated attacks. OpenAI is also introducing microgrants in the form of API credits for researchers wanting to quickly prototype new cybersecurity ideas.

On the offensive security front, OpenAI is looking inward with its own technology. The company detailed how it’s using AI-driven security agents alongside conventional strategies to hunt for threats and speed up incident response. To ensure those defenses hold up, they’ve partnered with adversarial operations firm SpecterOps to run continuous, realistic simulated attacks across corporate, cloud, and production environments. The goal here isn’t just to find holes but to use those exercises to generate advanced training data that sharpens their detection capabilities.

Perhaps the most tangible near-term result came from the company’s open-source security work. OpenAI claims its internal models have achieved state-of-the-art capability on public code security benchmarks and have already found real vulnerabilities in open-source software. Instead of sitting on those discoveries, the company says it will begin releasing security disclosures to the relevant open-source maintainers as it identifies and scales its bug-finding operations. It’s a practical move that puts pressure on other AI labs to start showing their homework, not just publishing benchmark scores.

💡 Key Takeaways

  1. OpenAI raised its maximum bug bounty payout from $20,000 to $100,000 to incentivize the discovery of high-impact, differentiated vulnerabilities.
  2. The company is now explicitly funding research into agentic security, signaling a growing internal concern about AI agents being exploited by sophisticated attacks.
  3. OpenAI claims its models are finding real vulnerabilities in open-source code and will begin issuing security disclosures to affected maintainers.
  4. Continuous red-teaming with partner SpecterOps is being used not just for defense testing but also to generate training data that improves AI threat detection.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

← Back to all articles