Mark RadarMARK RADAR
About
EN
Sign in

OpenAI Launches Safety Bug Bounty to Combat AI Misuse

1 reports · First detected 2026-03-30 · Last active 2026-03-30

Traditional bug-bounty programs generally focus on vulnerabilities in code, accounts or infrastructure, making them ill-suited to AI-native risks such as prompt injection and agent hijacking. OpenAI has therefore created a separate Safety Bug Bounty to complement its existing Security Bug Bounty and encourage researchers to disclose misuse pathways that could cause real-world harm.

OpenAI launched the program through Bugcrowd on March 25, 2026, offering rewards of up to $100,000 for critical findings. The scope covers risks involving agents and MCP, leaks of OpenAI’s internal information, and account and platform integrity. Prompt-injection or data-exfiltration attacks must have a reproducibility rate of at least 50%, while routine jailbreaks and simple content-policy violations are not eligible for rewards.

All Coverage

1 original reports

The Backstory

The history behind this event
After this
OpenAI Rolls Out ChatGPT Lockdown Mode to Counter Prompt-Injection Attacksfirst seen 2026-06-07 · 3 reports · similarity 0.78 · same topic: OpenAI

Prompt-injection attacks conceal malicious instructions in websites, files or emails, inducing AI systems to stray from users’ intentions and potentially transmit sensitive data externally. As ChatGPT connects to the web and corporate systems, the risk of data leakage has increased. OpenAI’s Lockdown Mode limits external connections, adding another layer of defense alongside sandboxing, monitoring, permissions and audit logs.

OpenAI first introduced Lockdown Mode and a “High Risk” label for enterprise plans on February 13, 2026, before expanding them to Free, Go, Plus, Pro and self-service Business plans on June 4. When enabled, the mode disables seven capabilities: live web access, images in responses, Deep Research, agent mode, Canvas network access, live connectors and file downloads. OpenAI said the feature can substantially reduce risk but cannot completely block attacks.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)