Real attackers don't think in bug bounty scopes

Last updated on September 20, 2026

A recent post on Hacking OpenAI and a bug bounty of $6,500 reminded me of an old problem. A security company was able to hack into private OpenAI repositories, but only got a small bounty. A company with a valuation of $852 billion paid a few pennies to researchers. In comparison, such data could be sold for hundreds of thousands on the black market.

For those who don't know, a bug bounty program is a way for companies to pay white-hat hackers (security researchers) to find vulnerabilities in their services and software. Bug bounties allow researchers to perform security research in a legal way and get paid for it. The hack was initiated through a hosted Discourse forum, but that forum was out of the scope of OpenAI's bug bounty program.

In bug bounty programs, there is usually a list of services the company wants to be tested and the rest of the services do not receive any bounty. In the case of the OpenAI hack, accessing the private data (from repositories) was in scope, but access to them was gained through Discourse, which was out of scope.

The reality is that real attackers don't care about scope. Their goal is to obtain sensitive data and sell it or extort the company. The security researchers demonstrated a harmless proof of concept that would allow them to access sensitive data if they wanted to. Scopes do not matter in real hacks and breaches. What matters is which information and systems could be accessed.

In this case, OpenAI used the scope rules as an excuse to pay less. This sort of behavior is not uncommon in bug bounties. All it does is discourage researchers from reporting vulnerabilities in a legal way.

The goal of bug bounty programs is to make the internet safer, but their rules often have many ways to screw over researchers. They try to find a balance between receiving reports and paying as little as possible.

It's also sad to see this from one of the AI companies that constantly brag about randomly hacking the internet without permission.


If you have any questions, feel free to ask them via e-mail displayed in the footer.
All articles on this website are written by a human.

Comments

There are no comments for this post. Be the first to share your thoughts.

Leave a comment