---
type: "post"
slug: "vercel-opens-a-1m-dollar-sandbox-escape-challenge"
title: "Vercel opens a 1M dollar Sandbox escape challenge"
description: "Vercel is paying up to $1M over two weeks to anyone who escapes its Sandbox, on the argument that a microVM without host-side network controls is only half an isolation boundary."
retrieval_nugget: "Vercel is paying up to $1M over two weeks to anyone who escapes its Sandbox, on the argument that a microVM without host-side network controls is only half an isolation boundary."
published_at: "2026-08-30"
updated_at: "2026-09-12"
record_date: "2026-09-01"
date_kind: "published_at"
topics: ["agent-security","agents","ai"]
entities: ["Vercel"]
source_url: "https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"
source_title: "$1 million hacker challenge for Vercel Sandbox"
source_domain: "vercel.com"
source_terms: ["Vercel","dollar","Sandbox","escape","challenge"]
summary_word_count: 194
schema_version: "newruntime-agent-readable-v0.2"
stable_id: "post:vercel-opens-a-1m-dollar-sandbox-escape-challenge"
status: "published"
source_urls: ["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"]
visuals: []
editorial_provenance: {"schema_version":"newruntime-editorial-copy-v1","content_status":"source_grounded_final","final_copy_sha256":"sha256:c9d40cfd1a783e4f13aef6f2990e6fb7a95919eac5a3af66145f491fa94d3dee","reviewed_at":"2026-09-12T10:00:00Z","source_evidence_count":1,"verified_claim_count":2,"site_analysis_schema_version":"newruntime-site-analysis-v1","site_object_kind":"field_note","observed_fact_count":2,"implication_count":1,"watch_condition_count":1,"related_record_count":3}
analysis: {"schema_version":"newruntime-site-analysis-v1","object_kind":"field_note","thesis":"Vercel opened a two-week programme paying up to $1,000,000 to researchers who can escape a Vercel Sandbox.","observed_facts":[{"text":"Vercel is paying up to $1,000,000 over two weeks to researchers who escape a Vercel Sandbox.","source_urls":["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"]},{"text":"An unsafeguarded open-weight model pointed at the Sandbox mapped the guest kernel, built a reproduction VM and wrote a fuzzer without escaping.","source_urls":["https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox"]}],"mechanism":"Vercel argues that agents running untrusted code do not need to cross a VM boundary to escape containment, because one network path the security model failed to account for is enough.","why_now":"Defenders hold a first-mover advantage that will not last, which is the stated reason to test the boundary on Vercel's schedule rather than an attacker's, in public.","implications":["Isolation holds only if both halves hold, the Firecracker microVM and the host-side network controls."],"evidence_boundary":"The post states the programme and the internal red-team result; it publishes no findings, scope document or payout record.","watch_conditions":["The condition to watch is whether Vercel publishes what was attempted and what held, because a challenge that ends in silence transfers no knowledge to anyone else running untrusted code."],"related_records":[{"url":"https://newruntime.com/posts/vm-isolation-is-only-one-agent-containment-boundary","relation":"Prior coverage of containment boundaries beyond the hypervisor."},{"url":"https://newruntime.com/posts/aisi-unsanctioned-agent-actions","relation":"Prior coverage of an incident that was an authorization failure, not a sandbox failure."},{"url":"https://newruntime.com/topics/sandbox","relation":"Topic hub for sandbox and isolation design."}]}
routes: {"html":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge/","markdown":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge.md","json":"https://newruntime.com/posts/vercel-opens-a-1m-dollar-sandbox-escape-challenge.json"}
---

# Vercel opens a 1M dollar Sandbox escape challenge

## Retrieval answer

Vercel is paying up to $1M over two weeks to anyone who escapes its Sandbox, on the argument that a microVM without host-side network controls is only half an isolation boundary.

Vercel opened a two-week programme paying up to $1,000,000 to researchers who can escape a Vercel Sandbox. The framing is more interesting than the prize: Vercel argues that agents running untrusted code do not need to cross a VM boundary to escape containment, because one network path the security model failed to account for is enough. Isolation holds only if both halves hold, the Firecracker microVM and the host-side network controls.

The reasoning is drawn from its own testing rather than theory. Vercel says its CTO pointed an open-weight model with no safeguards at the Sandbox; it did not escape, but it mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer. Defenders hold a first-mover advantage that will not last, which is the stated reason to test the boundary on Vercel's schedule rather than an attacker's, in public.

That is the same correction this site has made twice: [VM isolation is only one containment boundary](https://newruntime.com/posts/vm-isolation-is-only-one-agent-containment-boundary/), and [AISI's incident was an authorization failure rather than a sandbox failure](https://newruntime.com/posts/aisi-unsanctioned-agent-actions/). The [sandbox hub](https://newruntime.com/topics/sandbox/) collects the cases where the escape route was never the hypervisor.

The post states the programme and the internal red-team result; it publishes no findings, scope document or payout record. The condition to watch is whether Vercel publishes what was attempted and what held, because a challenge that ends in silence transfers no knowledge to anyone else running untrusted code.
