Case Studies◆ AI-generated · Sourced

Introducing the OpenAI Safety Bug Bounty Program

Introducing the OpenAI Safety Bug Bounty Program
TL;DR

OpenAI has launched the Safety Bug Bounty Program to solicit reproducible vulnerability reports against GPT-4, GPT-5.5, and related models—specifically targeting agentic vulnerabilities, prompt injection, and data exfiltration.

Background and Scope

The OpenAI Safety Bug Bounty Program is a core component of OpenAI’s operational safety framework, covering production models (e.g., GPT-4) and experimental releases (e.g., GPT-5.5 Bio), with explicit emphasis on real-world abuse vectors and deployment-level failure modes.

Target Vulnerability Classes

  • Agentic vulnerabilities: Unauthorized tool use, goal misgeneralization, or unbounded planning behavior in autonomous agent workflows;
  • Prompt injection: Direct or indirect injection leading to system prompt override, role hijacking, or context poisoning;
  • Data exfiltration: Leakage of training data fragments, user session artifacts, or sensitive metadata via model outputs.

Operational Principles

  • Reports must include full reproduction steps, impact chain analysis, and a minimal PoC;
  • Theoretical risks or non-triggering configuration issues are out of scope;
  • Bounties are tiered by severity (Critical/High/Medium), with maximum rewards up to $20,000 USD;
  • The GPT-5.5 Bio Bounty is a specialized track under this program, focused on domain-specific risks in biomedical AI—e.g., hallucinated clinical recommendations or misinterpreted genomic sequence semantics.
Umi Intelligence · Enroll / Contact

Turn “understanding the frontier” into “putting it to work”

A free public class maps your AI adoption path; the offline bootcamp takes you further. Reach out anytime.

✉ hello@umi6.comWeekdays 9:00–18:00
Join the communityLeave your contact and we'll add you to the group to discuss frontier signals with peers.