if you use a cluster of box's VMs (AI sandboxes 18x less expensive than vercel sandboxes) to pentest them super hard and succeed to break them this way I'll add $1,000,000 in box credits to the prize (~3100 years of 4vCPU 8gb runtime on box vs 176 on Vercel)
Agents can now exploit vulnerable sandbox boundaries, so we are testing ours in the open. $1,000,000 hacker challenge for Vercel Sandbox: • Escape the Firecracker microVM • Defeat the host-side network boundary • Up to $50k/report via @Hacker0x01 vercel.com/blog/one-million-…

Aug 18, 2026 · 8:07 PM UTC

10
3
1
92
13,840
RelevantRecentLikes
someone asked what if you find a critical vulnerability in box sandbox* (critical means you can penetrate another user's box without requiring to communicate with them and convince them to do certain suspicious actions) I'll do this: - 1st: same prize + 1k cash - 2nd: just 2y not 10 + 1k cash - 3rd: just 1y + 1k cash - 4th & more: only 1k cash
2
1
15
11,793
what's the criteria?
1
1
334
use box to pentest them and find the issue that rewards you their 1M prize by using box to pentest them in a way that being local wouldn't be practical with one local computer
1
3
291
what about finding a vulnerability in box itself?
2
4
465
should think of a good one and thinking of a good one takes time so I'll just write it here once I know
1
2
369
feels like a race, @rauchg
1
2
341
rauchg is elligible to the price btw
2
337
and there goes $1,000,00 (the sandbox was vibecoded)
2
79
Ok now that is an incentive
1
107
it's a credit???
122
18x cheaper than vercel sandboxes is the number that'll move people, not the bounty. the bounty just proves you believe the number. sent you a dm
80
Shit, can I just have a job instead?
57