Rather than waiting for an attacker to find the weak point in its AI execution environment, Vercel has opened a two-week public bug bounty on its Sandbox product — paying up to $1 million in total to any researcher who can escape it.
The programme, live from 18 August through 1 September 2026 on HackerOne, targets the security boundary around Vercel Sandbox: a Firecracker microVM running on bare-metal EC2 hosts, with a network firewall enforced on the host layer rather than inside the virtual machine.
Vercel's bet is informed by what has already gone wrong elsewhere. Recent incidents showed that AI agents running untrusted code do not necessarily need to breach a VM boundary to escape containment; an overlooked network path is enough. Inside each Vercel Sandbox, operator-supplied code runs two layers removed from the host (Linux container inside a Firecracker microVM), and the firewall intercepts outbound TCP and DNS outside the VM where the code cannot touch it. The $1 million challenge is an invitation for the security research community to prove or disprove those guarantees.
Payouts are per report and scoped to a single root cause. The ceiling for a vulnerability that lets an attacker read or modify another tenant's data is $50,000. Vercel has committed to publishing a full write-up after the programme closes — what broke, who found it, what was fixed — regardless of outcome. That transparency commitment is notable; most bug bounty programmes are silent about near-misses.
AI sandboxing has become a live problem as more enterprises deploy agents that execute code or call external services on behalf of users. Vercel's approach — test in the open before attackers do — reflects a broader shift in developer infrastructure: the security boundary around AI execution is now a first-class product concern, not an afterthought.
The HackerOne programme is open to all eligible researchers. If the reward pool is exhausted before 1 September, the programme closes early.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter