$1 million hacker challenge for Vercel Sandbox
Blog post from Vercel
Vercel has launched a two-week public HackerOne challenge offering up to $1 million in total rewards for researchers who can break the isolation of its Vercel Sandbox platform, reflecting concerns that secure execution of untrusted agent code requires both compute and network boundaries. Running from August 18 through September 1, 2026, the program offers up to $50,000 per report for demonstrated vulnerabilities that enable cross-tenant data access or modification, with rewards determined by severity and impact. Vercel Sandbox uses Firecracker microVMs on bare-metal EC2 hosts, placing user code in Linux containers inside dedicated guest kernels and enforcing outbound TCP, DNS, destination-policy, and credential controls from the host side. Eligible findings include microVM escapes, cross-tenant compute attacks, denial-of-service attacks against another sandbox, and firewall bypasses that enable unauthorized access, data exfiltration, or credential retrieval, while container escapes limited to the guest operating system are excluded. Researchers must submit live, reproducible proofs of concept through HackerOne rather than static-analysis findings, and Vercel plans to fix confirmed issues, pay successful participants, and later publish details on the discovered techniques and mitigations.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.