Physix Frontier · News Briefing Card (Hacker News · Oct 8, 2026)

Researcher Finds OpenAI Auth Bypass, Gets $300 Bounty

KEY FACTS

  • Researcher Fish discovered a vulnerability that bypasses authentication and sandbox protections.
  • The flaw allows access to OpenAI's paid models without an API key or account.
  • The vulnerability also affects OpenAI's internal Responses API.
  • OpenAI confirmed a $300 bounty payout through its Bugcrowd program.
  • Fish said the bounty was too low and that he has no incentive to report other vulnerabilities.

KEY DATA

300美元Bounty Amount
300,000美元Meta Highest Bounty

PHYSIX OBSERVATION

$300 for a vulnerability that lets you freeload off paid models is a price OpenAI simply cannot justify. The security community's outrage is warranted: a low bounty is effectively an incentive to trade exploits on the black market. If big tech wants to keep white hats around, it needs to show good faith commensurate with the risk—otherwise the next vulnerability may surface on the dark web before it ever reaches an inbox.

Source: Hacker News report