Fish reported a vulnerability that bypassed authentication and sandbox protections, granting unauthenticated access to paid models and OpenAI's internal Responses API. OpenAI's Bugcrowd program confirmed the $300 payout via email, but Fish called it too low, saying it gives him 'zero reason' to report more. The security community criticized the amount as an insult for such a high-impact issue, comparing it to Meta's bounties up to $300,000 and warning it discourages responsible disclosure.