Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenAI raised the top potential reward in its Security Bug Bounty program from $20,000 to $100,000 on March 26, 2025. The new amount applies to exceptional, differentiated critical findings; it is a maximum, not a guaranteed payment for every valid vulnerability report. OpenAI also announced a limited-time bonus promotion with its own eligibility rules and deadlines.

What changed in OpenAI’s bug bounty?

In its March 26, 2025 security announcement, OpenAI said it was increasing the maximum bounty for “exceptional and differentiated critical findings” to $100,000, up from $20,000. The company described the increase as recognition for high-impact security research that helps protect users and maintain trust.

The change raised the program’s ceiling, not every reward. A report must meet the program’s criteria, and the $100,000 figure is reserved for the narrowly defined critical-finding category. OpenAI separately announced a limited-time bonus promotion; its category-specific eligibility requirements and timelines determine whether a report qualifies for a promotional bonus.

How does the $100,000 maximum compare with the earlier program?

When OpenAI launched its bug bounty program in 2023, it described rewards from $200 for low-severity findings to as much as $20,000 for exceptional discoveries. The 2025 announcement raised that earlier top figure fivefold.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Program detail OpenAI’s 2023 announcement OpenAI’s March 2025 announcement
Maximum reward Up to $20,000 for exceptional discoveries Up to $100,000 for exceptional and differentiated critical findings
Low-severity starting figure $200 Not stated in the 2025 announcement
Submission and reward partner OpenAI said Bugcrowd would manage submission and reward processing The announcement does not establish whether that partnership remains current

These figures describe the announcements at those points in time; they do not establish a standard payout for a particular report. OpenAI’s 2023 announcement said it had partnered with Bugcrowd to manage submissions and reward processing. For current reporting instructions and program terms, use OpenAI’s designated Security Bug Bounty page.

What kind of report could qualify for the maximum?

The 2025 announcement identifies the maximum category as exceptional, differentiated critical findings. It does not say that every valid report, every critical-severity label, or every vulnerability automatically earns $100,000. The amount a report receives depends on how it meets the program’s criteria and the impact of the finding.

Keep the temporary bonus promotion separate from the standard bounty: it had its own eligible categories and deadlines. A report should be assessed against the applicable program terms rather than assuming a promotional bonus applies.

Where should you report a security vulnerability?

Use OpenAI’s designated Security Bug Bounty page for security vulnerabilities, including issues involving unauthorized access, platform integrity, or other security weaknesses. OpenAI’s 2023 launch announcement named Bugcrowd as its submission and reward-management partner, but that historical statement does not by itself confirm the current intake process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does the Safety Bug Bounty differ?

In March 2026, OpenAI introduced a separate Safety Bug Bounty for AI abuse and safety risks. OpenAI describes it as complementing the Security Bug Bounty, not replacing it. A vulnerability in OpenAI’s systems belongs in the security channel; the Safety Bug Bounty addresses qualifying safety or abuse risks. OpenAI says jailbreaks without demonstrable safety or abuse impact are generally outside the public Safety Bug Bounty’s scope.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.