ELSEIF
Your brief EB
354 stories from 110 feeds 398 clusters Refreshed 4 minutes ago next pull 18:07

SECURITY Signal 403

$1 million hacker challenge for Vercel Sandbox

Vercel launched a public HackerOne bounty program offering up to $1,000,000 USD total for researchers who can escape Vercel Sandbox isolation, with individual reports paying up to $50,000 USD.

WHY IT MATTERS

The challenge tests whether Firecracker microVM isolation and host-side network controls hold against real attacks, with confirmed findings becoming permanent fixes to the sandbox boundary. Engineers running untrusted code in microVM-based sandboxes should watch the results for boundary weaknesses that may apply to similar architectures.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The program runs from August 18 to September 1, 2026, or until the $1,000,000 USD pool is exhausted, with bounties ranging from $1,000 to $50,000 per report.

02

Scope covers escaping the Firecracker microVM to the EC2 host, reaching another tenant's sandbox, or defeating the host-side sandbox firewall without crossing the microVM.

03

Container namespace escapes reaching only the Firecracker guest OS are out of scope, and static-analysis-only findings will not be rewarded without a live proof of concept.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Vercel $1 million hacker challenge for Vercel Sandbox Open ↗