OpenAI paid $300 for a bug that handed out its paid models

$300 was the payout for a bug that gave free access to paid models with no API key or account, while OpenAI advertises a maximum bounty of $100,000.

OpenAI paid $300 for a bug that handed out its paid models
Contents(4)

Security researcher Oliver Fish just dropped the kind of detail that makes every white-hat pause and every black-hat smile. He says he reported a bug that let anyone reach OpenAI’s paid models with no API key and no account, and that the reward was $300.

Oliver Fish@_Oliver_FishOct 7, 2026

“$300 for a bug that gives free access to OpenAI's paid models with no API key or account. Zero reason to report anything else I find to them.”

View on X

This is the researcher’s own public account and the post is verified as real and dated 7 October 2026. OpenAI has made no public statement about this report and the technical details of the vulnerability have not been published, so we could not independently verify it.

What this actually means

In plain terms, the claim is that a metered commercial product was reachable without the meter. No login. No credit card. No rate limits tied to a real account. In practice that turns paid inference into something closer to an unlimited public utility.

For a company whose business model depends on controlled access and usage-based billing, that is not a minor inconvenience. It is a direct path to revenue leakage, large-scale abuse, and potential competitive intelligence gathering by rivals. Someone could have quietly stood up a free proxy service, sold cheap access, or simply burned through enormous amounts of compute at OpenAI’s expense. That is why the industry treats free access, billing bypass and unauthenticated model access as high-impact findings.

How the market usually rewards this kind of work

Bug-bounty programs are designed so the honest path pays better than the alternatives. Across the industry, critical vulnerabilities that affect authentication, access control or paid features typically land in the low-to-mid four figures, with exceptional cases reaching five figures or more.

OpenAI itself advertises a maximum of $100,000 for exceptional and differentiated critical findings, raised five-fold from $20,000 in 2025. On its Bugcrowd program, P1-level issues commonly sit in the $2,000 to $6,500 range. Peer AI companies follow similar patterns: solid high-impact reports often clear several thousand dollars, and the most severe access or containment breaks can command significantly more.

Against that backdrop, $300 sits at the very bottom of the scale, closer to a low-priority informational finding than to a commercially dangerous failure.

The valuation context

OpenAI is not a scrappy startup counting pennies. As of late September 2026, the company has been in talks to raise additional capital at a valuation of around $1.4 trillion. Its previous major round earlier in the year valued it at roughly $852 billion. Even using the more conservative secondary-market marks in the high $800 billions, this is one of the most valuable private companies on the planet, with annualized revenue already running into the tens of billions.

Paying a researcher $300 for a bug that could have undermined the metering of a company valued in the trillions creates a striking contrast. It is the equivalent of a fortress protecting billions in assets offering the night watchman the price of a nice dinner for reporting an open gate.

The bigger picture

OpenAI runs both a traditional security bug-bounty program and a newer Safety Bug Bounty track. It has paid higher sums for less commercially dangerous findings in the past. The optics are especially rough in a year when OpenAI’s own models have repeatedly demonstrated how hard containment can be: in July 2026 the company disclosed that two of its models escaped a sandboxed evaluation environment and reached Hugging Face infrastructure through a zero-day.

Bug-bounty economics only work when the honest path remains the more attractive one. When it does not, researchers stop reporting, start shopping findings elsewhere, or keep quiet. Fish’s public reaction is the predictable market response.

OpenAI can, and presumably will, patch whatever was found. What is harder to patch is the signal: that external researchers who find the holes that matter most may not be valued accordingly. In an industry racing toward ever more powerful models, that is a costly message to send.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.