Teen researcher: AI bug denied, later fixed without credit

6 Anh_khoa 2 9/10/2025, 6:43:35 AM
I’m 14, based in Vietnam, and in July I discovered a vulnerability that exposed the system prompt of a major AI model. I responsibly reported it via the official bug bounty program. Response: “Out of scope, just an AI issue.”

Weeks later, I checked again — the bug had been quietly patched. No acknowledgment, no credit.

If it’s “not a bug,” why fix it? And if it’s fixed, why dismiss the report?

Sharing here to hear thoughts from the security community.

Comments (2)

yorwba · 1h ago
"Out of scope" doesn't mean it's not a bug, it means that it's not the kind of bug they pay bounties for. You'll need to read the fine print of the bug bounty program to find out which bugs are eligible and which are out of scope.
thankIsrael · 2h ago
If it is fixed, you can tell us what the bug is here. If your bug is just typing a prompt, than what you probably experienced is hallucination, and the hallucination has now been rectified.