Anthropic Opens Security Bug Bounty Program to the Public on HackerOne
Original: Anthropic Opens Security Bug Bounty Program to the Public on HackerOne View original →
Public Bug Bounty Program Launched
Anthropic has opened its security bug bounty program to the public via HackerOne. Previously limited to a private group of vetted security researchers, the program is now open to anyone who wants to help identify vulnerabilities in Anthropic products.
Building on Private Program Success
The company ran the program privately within the security research community, and researchers findings directly strengthened Anthropic products. The private phase helped identify a range of vulnerabilities that internal teams might have missed.
How to Participate
Security researchers can now submit vulnerability reports through the Anthropic program page on HackerOne. Rewards range from $100 to $10,000 depending on the severity of the vulnerability found. AI-specific threat categories such as prompt injection, data exfiltration, and model manipulation are of particular interest.
Significance for AI Security
As AI models grow more capable and complex, external security scrutiny becomes increasingly vital. Anthropic opening the program publicly reflects a broader industry trend toward transparency and community-driven security research. Independent researchers can now formally contribute to making Claude safer for everyone.
Related Articles
Anthropic launched the Claude Security public beta for Enterprise customers, offering Opus 4.7-powered codebase scanning that auto-generates targeted patch suggestions, exports findings to CSV or Markdown, and integrates with Slack and Jira.
OpenAI on March 25 launched a public Safety Bug Bounty program on Bugcrowd for AI abuse, agentic misuse, and platform-integrity reports. The company says the new track complements its existing Security Bug Bounty rather than replacing it.
Axios reports the NSA is using Anthropic's Mythos Preview even as Pentagon officials call the company a supply-chain risk. The clash puts AI safety limits, federal cyber demand, and procurement politics in the same room.
Comments (0)
No comments yet. Be the first to comment!