A $1 Million Hacker Challenge for Vercel Sandbox
Key point
Vercel is launching a $1 million hacker challenge to verify the security boundaries of its sandbox technology.
Details
When AI agents execute untrusted code, microVM has become the standard technology for isolation. However, recent research has revealed that isolation can be escaped without crossing the VM boundary if network boundaries are not properly managed.
Vercel is running a two-week public hacker challenge via HackerOne to proactively verify security. This challenge aims to test the isolation performance of Vercel Sandbox.
- Total prize pool: Up to 1,000,000 USD
- Maximum reward per report: 50,000 USD (for accessing/modifying other tenants' data)
- Period: August 18, 2026 – September 1, 2026 (or until the prize pool is exhausted)
Vercel Sandbox runs on bare-metal EC2 hosts. Each sandbox uses a Firecracker microVM with a dedicated guest kernel, and the security boundary is a microVM rather than a container. Therefore, code provided by operators runs two steps removed from the host.
Researchers can attempt to breach the following two boundaries:
- Compute boundary: Escaping the Firecracker microVM to reach the EC2 host, or accessing/manipulating other tenants' sandboxes.
- Network boundary: Bypassing the sandbox firewall to reach unauthorized destinations or exfiltrate data.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.