Security researcher Oliver Fish just dropped the kind of detail that makes every white-hat pause and every black-hat smile. He says he reported a bug that let anyone reach OpenAI’s paid models with no API key and no account, and that the reward was $300.
“$300 for a bug that gives free access to OpenAI's paid models with no API key or account. Zero reason to report anything else I find to them.”
View on XThis is the researcher’s own public account and the post is verified as real and dated 7 October 2026. OpenAI has made no public statement about this report and the technical details of the vulnerability have not been published, so we could not independently verify it.
What this actually means
In plain terms, the claim is that a metered commercial product was reachable without the meter. No login. No credit card. No rate limits tied to a real account. In practice that turns paid inference into something closer to an unlimited public utility.
For a company whose business model depends on controlled access and usage-based billing, that is not a minor inconvenience. It is a direct path to revenue leakage, large-scale abuse, and potential competitive intelligence gathering by rivals. Someone could have quietly stood up a free proxy service, sold cheap access, or simply burned through enormous amounts of compute at OpenAI’s expense. That is why the industry treats free access, billing bypass and unauthenticated model access as high-impact findings.
How the market usually rewards this kind of work
Bug-bounty programs are designed so the honest path pays better than the alternatives. Across the industry, critical vulnerabilities that affect authentication, access control or paid features typically land in the low-to-mid four figures, with exceptional cases reaching five figures or more.
