October 1, 2026
The Fastest Bug Bounty Win I’ve Ever Read About Took 3 People, 72 Hours, and $3,000 in API Costs
They used Claude to break into OpenAI, got paid $6,500, and then got $115,000 from Meta for the same bug class. Here’s what that actually…

By Riya Limba
3 min read
They used Claude to break into OpenAI, got paid $6,500, and then got $115,000 from Meta for the same bug class. Here's what that actually means for beginners.
I read the Hacktron AI disclosure on a Sunday and couldn't stop thinking about the numbers.
Three researchers. 72 hours. About $3,000 in API costs. A working exploit chain into OpenAI's internal systems. A $6,500 bounty.
Then they took the same vulnerability class to Meta and got $115,000 .
Same researchers. Same skill set. Same bug category. A 17x difference in payout.
I sat with that for a long time.
What They Actually Did
The researchers started with OpenAI's community forum. The forum runs on Discourse, which doesn't recognize HEIC images — the format iPhones use by default. When you upload one, Discourse silently hands it to ImageMagick, which calls a library called libheif to decode it.
libheif had a heap buffer overflow. The patch existed upstream, but the Debian container running Discourse hadn't applied it. The researchers used Claude to analyze the Docker image and find the missing patch .
By the time they were done, they had remote code execution on the forum server. They chained it with a single sign-on misconfiguration and walked into OpenAI's internal GitHub. They made a harmless pull request to prove access, reported it, and walked away .
OpenAI fixed it in 14 hours. Paid $6,500.
The Part That Should Make You Think
The researchers didn't stop after OpenAI.
They kept hunting the same vulnerability class — memory corruption in HEIC/HEIF parsing — across other platforms. Slack. GitHub Enterprise. Next.js. And Meta.
Meta's Facebook and Instagram had the same class of bug. Memory corruption in server-side image conversion. Potential remote code execution. Meta paid $115,000 .
The OpenAI payout was for the in-scope portion of the chain. The forum was out of scope. The identity chain was in scope. The $6,500 reflected what OpenAI decided that access was worth.
Meta decided the same class of bug was worth 17x more.
What I'm Taking From This
I've been learning bug bounty for months. I've found one confirmed bug. I'm waiting to be paid.
Reading this disclosure, I felt something I hadn't expected: clarity.
Not about the money. About the work.
The bug wasn't exotic. It wasn't a zero-day in OpenAI's models. It was a missing patch in a dependency. A library version that didn't get updated. A configuration that wasn't hardened.
That's the kind of bug a beginner can find.
You don't need to understand neural networks. You don't need to reverse engineer proprietary AI. You need to understand how software gets deployed — and where the gaps are between what should have been patched and what actually was.
The researchers used Claude to analyze the Docker image. That's not cheating. That's using the tools available. The skill was in knowing what to look for and understanding why the patch wasn't there.
The Uncomfortable Math
I've written before about Microsoft's average payout dropping from $49,000 to $35,000 even as total spending hit a record $20 million . About Intel closing its bounty program entirely. About curl ending its program because AI slop made triage unsustainable.
This case adds another layer: the same skill is worth wildly different amounts depending on where you point it.
The researchers didn't get paid $6,500 because OpenAI is cheap. They got paid $6,500 because the forum was out of scope and the in-scope portion was limited.
They got paid $115,000 from Meta because Meta's scope definition and bounty tiers valued that access differently.
The lesson isn't "OpenAI bad, Meta good." It's that the target matters as much as the technique.
What I'm Doing Differently
I'm not going to pretend I can game this system perfectly. But I can do three things:
First, I'm reading scope definitions like a contract. "Out of scope" doesn't mean "don't test." It means "don't expect to be paid for what you find there." If my chain crosses scope lines, the payment might only cover the in-scope link.
Second, I'm paying attention to dependency versions. The bug was a missing patch. I'm learning to look at what libraries are running, what versions they're on, and whether the patches exist but haven't been applied.
Third, I'm remembering that the same technique can be worth $500 or $50,000. The difference isn't always skill. It's often program selection.
I don't know which program is right for me yet. But I know now that the question matters.
If you're also navigating the gap between what bugs are worth and what they pay, I write about what I'm actually learning — numbers included. Follow for more field notes from the bottom of the learning curve.