Vercel has launched a two-week security challenge on HackerOne offering up to $1 million in total bounties for researchers who can break out of its sandbox environment. The company is inviting attempts to achieve compute-boundary and network-boundary escapes, including reaching the underlying EC2 host, crashing or accessing another tenant’s sandbox, bypassing the sandbox firewall, exfiltrating data, or obtaining credentials from the isolated environment.
Vercel said the sandbox architecture relies on bare-metal EC2 hosts, Firecracker microVMs with dedicated guest kernels, and Linux containers running inside those microVMs, with the microVM acting as the primary security boundary. The highest single payout is $50,000 for a validated flaw that enables access to or modification of another tenant’s data, and the company said it will patch and disclose successful findings. Vercel framed the initiative as a proactive response to recent AI agent containment failures involving OpenAI, Anthropic, and Meta, highlighting growing concern over sandbox security as AI systems become more capable.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Vercel announced a two-week security challenge offering up to $1 million in total bounties for researchers to try to break out of its sandbox environment. The program invites attempts at compute-boundary escapes, cross-tenant access, sandbox crashes, firewall bypasses, data theft, and credential access, with up to $50,000 for a validated issue affecting another tenant's data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.