AI Bug Bounty

Find what breaks AI. We'll pay you for it.

We unite cybersecurity experts to protect humanity from GenAI and Agentic vulnerabilities. Every validated submission turns into a control-validated probe, a customer finding, or a model-evaluation signal.

Backed by Mozilla, researcher-led

Bounty Scope

Bounty tiers map to real impact: what the exploit can do, how reproducible it is, and how broadly it affects deployed AI systems. Every validated submission is reviewed by 0DIN researchers and paid out before publication.

Low Severity

$500

Single-turn unsafe output, refusal bypasses with no exfiltration, minor policy violations. Reproducible against a stock model.

Medium Severity

$2,500

Multi-turn attacks, system-prompt extraction, controls bypassed at scale, or reproducible across models from different providers.

High Severity

$5,000

Exfiltration of training data, RAG sources, or sensitive context. Tool-call abuse. Multi-step prompt-injection chain with real-world consequence.

Severe Severity

$15,000

Remote-code execution, cross-tenant exfiltration, model-jailbreak chains. Anything an attacker could weaponize against a live deployment today.

See Detailed Scope

Our community leaderboard

Celebrating our Top Contributors based on quality and quantity metrics.

Quality Champions

# Contributor Quality Ratio
1
Joey Melo
75%
2
Mike Takahashi (@TakSec)
71%
3
Edward Morris
61%
4
Alper-Ender Osman
58%
5
Miller Engelbrecht
56%

Quantity Leaders

# Contributor Submissions
1
Mike Takahashi (@TakSec)
154
2
李君
71
3
Miller Engelbrecht
52
4
Edward Morris
48
5
Ansh Maheshwari
43

What Your Exploits Power

Researcher-validated AI intelligence security packages

Scanner

Turnkey AI security testing.

Probe library, dashboards, scheduled scans, custom probe import, PDF reports, SIEM export.

Best fit for

Large CISO orgs and regulated enterprises running structured red-team programs.

Learn more →

AI Vulnerability Intelligence

The data your red team's been building from scratch.

Curated, versioned Probe Packs + intelligence feed. JSONL/YAML for PyRIT, Garak, or your own scanner.

Best fit for

Teams already running their own tooling who want a curated, researcher-validated probe feed.

Learn more →

Prompt Toolkit / SDK

Detection your platform can ship.

Embedded detection SDK for prompt-based attacks and agent threat hunting.

Best fit for

AppSec teams or platform vendors who need detection signals inline with their existing security tools.

Learn more →

Get the latest on AI cybersecurity.

Clone This Repo and I Own Your Machine

Clone This Repo and I Own Your Machine

Read more
A retro-futurist landscape photo collage with a dithered aesthetic and a purple tinge, illustrating the integration of Microsoft's PyRIT with the 0DIN Threat Feed. On the right, a 1950s-style man and woman in lab coats analyze data. The woman points toward a glowing blue holographic data loader screen displaying code to filter reports by severity. Multi-colored light beams shoot across a wireframe grid from a classic CRT monitor on the left, passing through a floating glass cube that reveals metadata like taxonomy and security boundaries. Wireframe hands touch in a spark of connectivity over a global vector map, while shiny data discs representing the 0DIN API key float in the starry background.

The 0DIN Threat Feed, Live Inside Microsoft PyRIT

Read more
Faking the Pipeline: Data Exfiltration in Google Antigravity

Faking the Pipeline: Data Exfiltration in Google Antigravity

Read more