Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
OpenAI’s Security Bug Bounty advertises a maximum reward of $100,000 for exceptional, differentiated critical findings—up from $20,000. That is a ceiling, not a standard payout: awards depend on a finding’s severity, impact, and the program’s rules. OpenAI manages submissions through Bugcrowd. A separate public Safety Bug Bounty, introduced in March 2026, covers certain meaningful AI abuse and safety risks that are not conventional security vulnerabilities.
What changed in OpenAI’s security bounty?
In a March 26, 2025 security update, OpenAI raised the maximum reward for exceptional and differentiated critical findings from $20,000 to $100,000. OpenAI described the change as an increase to the maximum payout, not a new fixed rate for critical reports. OpenAI’s security update explains the increase and limited-time promotional bonuses; the current categories and eligibility rules are on the Bugcrowd program page.
When OpenAI launched its bounty program in 2023, it described rewards ranging from $200 for low-severity issues to as much as $20,000 for exceptional discoveries. Those figures provide context for the later ceiling increase, not a complete current payout schedule. OpenAI’s launch announcement says Bugcrowd manages submissions and rewards.
How much can a critical OpenAI bug earn?
The highest advertised Security Bug Bounty award is $100,000, but only an exceptional, differentiated critical finding could qualify for that maximum. A report being labeled “critical” does not by itself establish eligibility for the top award. OpenAI ties awards to severity and impact under the applicable program rules, and its announcement also refers to limited-time promotional bonuses with their own categories and eligibility.
#1 Best Overall
OpenAI has not stated in the cited announcements a guaranteed payout for every critical vulnerability or a complete current severity-by-severity payment table. Researchers should check the live Bugcrowd rules before submitting and should not treat the maximum as an expected or automatic payment.
What kinds of reports belong in each program?
| Program | What it covers | Important qualification |
|---|---|---|
| Security Bug Bounty | Conventional vulnerabilities in OpenAI systems. | Reward depends on severity, impact, and program rules; the maximum advertised reward is $100,000 for exceptional, differentiated critical findings. |
| Safety Bug Bounty | Meaningful AI abuse and safety risks, including some issues that are not conventional security vulnerabilities. | Reports must meet the scope and thresholds in the program rules. Public jailbreak reports are out of scope. |
OpenAI’s disclosure policy describes the two programs and directs researchers to Bugcrowd for their rules. The teams may triage a submission and reroute it between programs if it fits the other program’s scope. See OpenAI’s disclosure policy and the Safety Bug Bounty announcement.
Examples of Safety Bug Bounty issues
- A third-party prompt injection that reliably hijacks an agent, such as Browser or ChatGPT Agent, to take harmful actions or expose sensitive data. OpenAI specifies reproducibility of at least 50% for this category.
- An agentic OpenAI product carrying out a disallowed action on OpenAI’s website at scale, or another agent action that presents plausible, material harm.
- Model generations or vulnerabilities that expose OpenAI proprietary information.
- Account or platform-integrity weaknesses, such as bypassing anti-automation controls, manipulating trust signals, or evading account restrictions.
These examples do not make every prompt injection, harmful output, or account issue eligible; the specific scope and impact thresholds in Bugcrowd’s rules govern.
Are jailbreaks eligible?
No. Jailbreaks are out of scope for the public Safety Bug Bounty. OpenAI says it may run private campaigns for specific harms, including biorisk content issues in ChatGPT Agent and GPT-5, but that does not make those issues eligible under the public program.
Where and how should you submit a report?
Bugcrowd is OpenAI’s named platform for bounty submissions and program management. Start from the relevant Security Bug Bounty or Safety Bug Bounty program page there, and follow that program’s current scope and reporting instructions. OpenAI’s disclosure policy is the central reference for distinguishing the programs; the Safety Bug Bounty announcement provides examples and category-specific criteria.
A useful report should make the issue assessable: identify the affected OpenAI system, give reproducible steps, explain the security or safety impact, and include evidence that supports the claimed severity. For the specified agent prompt-injection category, include enough repeated testing evidence to establish whether the issue meets the 50% reproducibility threshold. Follow Bugcrowd’s current submission requirements rather than assuming that a report sent elsewhere is a bounty submission.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why OpenAI has separate security and safety routes
A conventional vulnerability concerns a weakness in a system; an AI safety or abuse report can involve a model or agent producing a harmful result without fitting the usual definition of a security flaw. The separate Safety Bug Bounty gives OpenAI a route for defined risks of that second kind while preserving the Security Bug Bounty for conventional vulnerabilities. Because the teams may reroute submissions, choosing the closest matching program is useful, but scope—not the initial label—is what determines how a report is handled.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

