SECURITY Signal 403
$1 million hacker challenge for Vercel Sandbox
Vercel launched a public HackerOne bounty program offering up to $1,000,000 USD total for researchers who can escape Vercel Sandbox isolation, with individual reports paying up to $50,000 USD.
The challenge tests whether Firecracker microVM isolation and host-side network controls hold against real attacks, with confirmed findings becoming permanent fixes to the sandbox boundary. Engineers running untrusted code in microVM-based sandboxes should watch the results for boundary weaknesses that may apply to similar architectures.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The program runs from August 18 to September 1, 2026, or until the $1,000,000 USD pool is exhausted, with bounties ranging from $1,000 to $50,000 per report.
Scope covers escaping the Firecracker microVM to the EC2 host, reaching another tenant's sandbox, or defeating the host-side sandbox firewall without crossing the microVM.
Container namespace escapes reaching only the Firecracker guest OS are out of scope, and static-analysis-only findings will not be rewarded without a live proof of concept.
THE CLUSTER
↗