1 hr ago
OpenAI Code Access Highlights Falling Costs of AI Security Attacks
Security researchers tested OpenAI’s systems and found a way to reach employee accounts and internal computer code.
They used paid AI tools that cost about $200 a month.
Their broader research used less than $3,000 worth of tokens.
The work took a few days of setup and a few more hours for the OpenAI-related testing.
OpenAI paid them $6,500 through its bug-bounty program.
The researchers also entered a community forum, but that forum used Discourse and was outside the program’s rules.
Because of that, OpenAI paid nothing for the forum part.
The story raises concerns that powerful security work may now be cheaper and easier to perform.
Security researchers reached multiple OpenAI employee accounts and its internal source-code repository through a reported chain of findings.
OpenAI paid the researchers $6,500 under its bug-bounty rules and published severity and scope schedules.
The researchers used ordinary paid AI-model subscriptions costing about $200 monthly, while broader token spending remained below $3,000.
Testing the OpenAI community forum, which runs on third-party software called Discourse, was excluded from the bounty program and earned no payment.
The incident suggests AI tools may reduce the cost and expertise needed to conduct serious security research or attacks.
- Who
- Security researchers and OpenAI.
- What
- Researchers reached multiple OpenAI employee accounts and the company’s internal source-code repository, receiving a $6,500 bounty.
- Where
- OpenAI systems, including its internal code repository, employee accounts, and a community forum running on Discourse.
- When
- The article does not specify when the testing occurred.
- Why
- The researchers were conducting legitimate white-hat security research and reported their findings without causing harm.
Scope and risk concerns
Program rules and payout rationale
Forum testing
Scope and risk concerns
The forum served as an entry point, illustrating how attackers may use systems excluded from a company’s bounty program to reach company assets.
Program rules and payout rationale
OpenAI stated that testing the forum was explicitly excluded because it runs on third-party software, so the forum intrusion was not eligible for payment.
Meaning of the $6,500 bounty
Scope and risk concerns
The payout highlights a potentially troubling gap between the low cost of finding access and the high value of the internal code that was reached.
Program rules and payout rationale
The amount followed OpenAI’s published severity and scope rules, and the researchers used a legitimate program without publicly complaining about the payment.
Key facts
- OpenAI bounty
- $6,500
- AI-tool subscription cost
- About $200 per month
- Broader token spending
- Under $3,000
- Access reached
- Multiple employee accounts and the internal source-code repository
- Excluded system
- OpenAI’s community forum, which runs on Discourse
- Forum payout
- Nothing, because forum testing was outside the bounty program’s scope
Quotes
An unnamed security executive
A security executive quoted in coverage of the incident
“for $200 a month, anyone can use these tools, and if it can happen to a company as well-resourced as OpenAI, it can happen to anyone.”
wionews.com





