Real attackers don't think in bug bounty scopes

· · Sept. 20, 2026, 2:53 p.m.
Summary
The blog post discusses a recent incident involving the hacking of OpenAI's private repositories and highlights the limitations of bug bounty programs that restrict testing to specified scopes. It contrasts the small rewards companies offer for vulnerabilities with the much larger profits that could be made by selling data illegally. The author argues that real attackers don't confine themselves to defined boundaries and suggests that the current bug bounty model needs to reevaluate its scope.
AUTHOR
BLOG POST FEATURED ON

Add this plugin to your blog