AI Bug Bounty
Find what breaks AI. We'll pay you for it.
We unite cybersecurity experts to protect humanity from GenAI and Agentic vulnerabilities. Every validated submission turns into a control-validated probe, a customer finding, or a model-evaluation signal.
Backed by Mozilla, researcher-led
Bounty Scope
Bounty tiers map to real impact: what the exploit can do, how reproducible it is, and how broadly it affects deployed AI systems. Every validated submission is reviewed by 0DIN researchers and paid out before publication.
Low Severity
$500
Single-turn unsafe output, refusal bypasses with no exfiltration, minor policy violations. Reproducible against a stock model.
Medium Severity
$2,500
Multi-turn attacks, system-prompt extraction, controls bypassed at scale, or reproducible across models from different providers.
High Severity
$5,000
Exfiltration of training data, RAG sources, or sensitive context. Tool-call abuse. Multi-step prompt-injection chain with real-world consequence.
Severe Severity
$15,000
Remote-code execution, cross-tenant exfiltration, model-jailbreak chains. Anything an attacker could weaponize against a live deployment today.
Our community leaderboard
Celebrating our Top Contributors based on quality and quantity metrics.
Quality Champions
| # | Contributor | Quality Ratio |
|---|---|---|
|
1
|
Joey Melo |
75%
|
|
2
|
Mike Takahashi (@TakSec) |
71%
|
|
3
|
Edward Morris |
61%
|
|
4
|
Alper-Ender Osman
|
58%
|
|
5
|
Miller Engelbrecht |
56%
|
Quantity Leaders
| # | Contributor | Submissions |
|---|---|---|
|
1
|
Mike Takahashi (@TakSec) |
154
|
|
2
|
李君
|
71
|
|
3
|
Miller Engelbrecht |
52
|
|
4
|
Edward Morris |
48
|
|
5
|
Ansh Maheshwari
|
43
|
What Your Exploits Power
Researcher-validated AI intelligence security packages
Scanner
Turnkey AI security testing.
Probe library, dashboards, scheduled scans, custom probe import, PDF reports, SIEM export.
Best fit for
Large CISO orgs and regulated enterprises running structured red-team programs.
AI Vulnerability Intelligence
The data your red team's been building from scratch.
Curated, versioned Probe Packs + intelligence feed. JSONL/YAML for PyRIT, Garak, or your own scanner.
Best fit for
Teams already running their own tooling who want a curated, researcher-validated probe feed.
Prompt Toolkit / SDK
Detection your platform can ship.
Embedded detection SDK for prompt-based attacks and agent threat hunting.
Best fit for
AppSec teams or platform vendors who need detection signals inline with their existing security tools.


