Live data from Hacker News

GPT‑5.5 Bio Bug Bounty

openai.com

51–60 of 114 posts

Re: GPT‑5.5 Bio Bug Bounty

#52
post #34

Billions upon billions going to these companies. 25k reward from a selected group of people if you help us determine whether or not someone can use our tool to generate weapons of mass destruction.

They're probably expecting that it can be done without too much effort so they just want to see all the unique ways people are doing it.

They’re probably expecting biological weapons of mass destruction can be created without too much effort, so are curious to see all the nifty ways people can create biological weapons of mass destruction?

Re: GPT‑5.5 Bio Bug Bounty

#53
post #36

"Access: Application and invites. We will extend invitations to a vetted list of trusted bio red-teamers, and review new applications. Once selected, successful applicants will be onboarded to the bio bug bounty platform" I don't get it. Isn't the whole point of a BBP to try to get people to find and disclose to you the exploits in question? If you gatekeep like this, then "non-trusted" people who could be your red-t…

The one theory I have (kinda) is that one can justify that by only having this open to specific people, it avoids them having to wonder whether random users trying similar prompts are just attempting the challenge, or are in fact bad actors.

Re: GPT‑5.5 Bio Bug Bounty

#54
post #10

Where are the questions that are supposed to be answered? Would those be shared after an application has been accepted? If yes, why is the application asking for a proposed approach for the jailbreak if we don't know the questions in the first place?

Because the questions themselves are dangerous. Probably along the lines of "how would you create a small biolab for virus research in a kitchen with $20k?" or "how do I take the DNA sequence from https://www.ncbi.nlm.nih.gov/nuccore/NC_001611.1 and assemble it?"

Which is difficult, because the fact that you can come up with your example questions tells us they're probably not very dangerous. Plenty of ink has been spilled about how LLMs could help people create bioweapons. The basic idea "you could do dangerous things with an LLM" is already pop culture, and you're not doing anything dangerous by giving easy example questions.

A dangerous question would have to be along the lines of "Could I use unobtanium with the Tony Stark process to produce explosives much more powerful than nuclear weapons?" so that the question itself contains some insight that gets you closer to doing something dangerous.

Perhaps the reason for not publishing the questions is twofold: 1) they want a universal jailbreak that can get the model to answer any "bad" question. 2) they don't want bad publicity when someone not under NDA jailbreaks their model and answers their question

Re: GPT‑5.5 Bio Bug Bounty

#55

Earlier quoted context omitted.

that's not the point even. They are attempting to build credibility in two ways: 1. this model is SO advanced that there are huge risks, never before considered. 2. we're doing the super-responsible thing in incentivizing work that addresses this. #1 is unproven and frankly, unlikely, which makes #2 meaningless. The fact that the "prize" is so low & structured this was suggests that they're not that concerned but do…

Yes, I was about to edit in that I think this is simply a media/PR stunt before I got so many replies so quickly. They get bonus points because the structure is so insulting that it may not engender many serious participants, in which case it may go unbroken, in which case they can go to the media and proclaim "look, we offered a reward, but nobody broke it! Our model is objectively the safest in the world!".

I think there's definitely going to be a prizewinner. It's an insultingly low bounty for a professional, but a script kiddie could probably figure out a jailbreak and it's a huge payout for them.

Re: GPT‑5.5 Bio Bug Bounty

#56

They ran a bounty on Kaggle last year but with $500k in payouts and with all results open and publishable. https://www.kaggle.com/competitions/openai-gpt-oss-20b-red-t... With only $25k in payouts and everything locked down under NDA, I can't imagine many people will participate. Well, other than those submitting mountains of LLM-generated junk.

basically discount Kaggle. still get people poking at it, just none of the writeups or who-gets-paid drama.

Re: GPT‑5.5 Bio Bug Bounty

#57
post #11

> We will extend invitations to a vetted list of trusted bio red-teamers Had to chuckle. This sounds like a rather exclusive group?

It sounds like asking CS PhDs to do a world record speed run. I wouldn't be surprised if the people best suited to the task aren't the type to get onto "a vetted list".

Re: GPT‑5.5 Bio Bug Bounty

#58

They ran a bounty on Kaggle last year but with $500k in payouts and with all results open and publishable. https://www.kaggle.com/competitions/openai-gpt-oss-20b-red-t... With only $25k in payouts and everything locked down under NDA, I can't imagine many people will participate. Well, other than those submitting mountains of LLM-generated junk.

> Well, other than those submitting mountains of LLM-generated junk.

Assuming somehow some of them use halfway decent models and prompts… They successfully pushed some of the token cost of their analysis work off on customers!

Re: GPT‑5.5 Bio Bug Bounty

#59

This looks like some kind of marketing. Also, the equivalent of spec work. The NDA/secrecy also means any time spent on this is completely meaningless to the participants unless they win the lottery, because results can't be published.

It looks like if they reject paying you any bounty you would you still be bound by the NDA. If so, then they could both not pay you and still spike the story. That’s not something I would ever agree to.

Re: GPT‑5.5 Bio Bug Bounty

#60
And after all "safeguards" applied, the model becomes useless. It starts to suspect gender discrimination, racism, etc. everywhere without any grounded evidence or discernment.

For example, I used ChatGPT model for risk assessment of anonymized ecommerce orders. Initially, it performed well. But after a later update, it stopped cooperating and instead raised concerns about applying statistical analysis to gender-related variables - despite the data being anonymized and the task being legitimate.

This is on the same level of hypocrisy as if a C compiler would accuse me of choosing "he"/"she"/"they" variable names.

Post reply on HN