Field note
Vercel opened a two-week programme paying up to $1,000,000 to researchers who can escape a Vercel Sandbox. The framing is more interesting than the prize: Vercel argues that agents running untrusted code do not need to cross a VM boundary to escape containment, because one network path the security model failed to account for is enough. Isolation holds only if both halves hold, the Firecracker microVM and the host-side network controls.
The reasoning is drawn from its own testing rather than theory. Vercel says its CTO pointed an open-weight model with no safeguards at the Sandbox; it did not escape, but it mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer. Defenders hold a first-mover advantage that will not last, which is the stated reason to test the boundary on Vercel's schedule rather than an attacker's, in public.
That is the same correction this site has made twice: VM isolation is only one containment boundary, and AISI's incident was an authorization failure rather than a sandbox failure. The sandbox hub collects the cases where the escape route was never the hypervisor.
The post states the programme and the internal red-team result; it publishes no findings, scope document or payout record. The condition to watch is whether Vercel publishes what was attempted and what held, because a challenge that ends in silence transfers no knowledge to anyone else running untrusted code.