{"type":"post","slug":"vercel-opens-a-1m-dollar-sandbox-escape-challenge","title":"Vercel opens a 1M dollar Sandbox escape challenge","description":"Vercel is paying up to $1M over two weeks to anyone who escapes its Sandbox, on the argument that a microVM without host-side network controls is only half an isolation boundary.","retrieval_nugget":"Vercel is paying up to $1M over two weeks to anyone who escapes its Sandbox, on the argument that a microVM without host-side network controls is only half an isolation boundary.","published_at":"2026-08-30","updated_at":"2026-09-12","record_date":"2026-09-01","date_kind":"published_at","topics":["agent-security","agents","ai"],"entities":["Vercel"],"source_url":"https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox","source_title":"$1 million hacker challenge for Vercel Sandbox","source_domain":"vercel.com","source_terms":["Vercel","dollar","Sandbox","escape","challenge"],"summary_word_count":194,"schema_version":"newruntime-agent-readable-v0.2","stable_id":"post:vercel-opens-a-1m-dollar-sandbox-escape-challenge","status":"published","source_urls":["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"],"visuals":[],"editorial_provenance":{"schema_version":"newruntime-editorial-copy-v1","content_status":"source_grounded_final","final_copy_sha256":"sha256:c9d40cfd1a783e4f13aef6f2990e6fb7a95919eac5a3af66145f491fa94d3dee","reviewed_at":"2026-09-12T10:00:00Z","source_evidence_count":1,"verified_claim_count":2,"site_analysis_schema_version":"newruntime-site-analysis-v1","site_object_kind":"field_note","observed_fact_count":2,"implication_count":1,"watch_condition_count":1,"related_record_count":3},"analysis":{"schema_version":"newruntime-site-analysis-v1","object_kind":"field_note","thesis":"Vercel opened a two-week programme paying up to $1,000,000 to researchers who can escape a Vercel Sandbox.","observed_facts":[{"text":"Vercel is paying up to $1,000,000 over two weeks to researchers who escape a Vercel Sandbox.","source_urls":["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"]},{"text":"An unsafeguarded open-weight model pointed at the Sandbox mapped the guest kernel, built a reproduction VM and wrote a fuzzer without escaping.","source_urls":["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"]}],"mechanism":"Vercel argues that agents running untrusted code do not need to cross a VM boundary to escape containment, because one network path the security model failed to account for is enough.","why_now":"Defenders hold a first-mover advantage that will not last, which is the stated reason to test the boundary on Vercel's schedule rather than an attacker's, in public.","implications":["Isolation holds only if both halves hold, the Firecracker microVM and the host-side network controls."],"evidence_boundary":"The post states the programme and the internal red-team result; it publishes no findings, scope document or payout record.","watch_conditions":["The condition to watch is whether Vercel publishes what was attempted and what held, because a challenge that ends in silence transfers no knowledge to anyone else running untrusted code."],"related_records":[{"url":"https://newruntime.com/posts/vm-isolation-is-only-one-agent-containment-boundary","relation":"Prior coverage of containment boundaries beyond the hypervisor."},{"url":"https://newruntime.com/posts/aisi-unsanctioned-agent-actions","relation":"Prior coverage of an incident that was an authorization failure, not a sandbox failure."},{"url":"https://newruntime.com/topics/sandbox","relation":"Topic hub for sandbox and isolation design."}]},"routes":{"html":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge/","markdown":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge.md","json":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge.json"}}
