$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
Vercel ran a two-week bug bounty with a $1 million prize pool for escaping the Firecracker sandbox used for AI agent code. It received 1,285 reports and confirmed 1 critical, 7 high and 15 medium vulnerabilities, paying out about $325,000.
- 1,285 reports in two weeks, payouts of about $325,000
- Confirmed 1 critical, 7 high and 15 medium vulnerabilities
- Two Linux kernel network stack flaws: memory leak and host crash
- No report gave access to real customer data
Read next
Security