OpenAI Makes Its GPT-5.6 Bio Bounty Permanent and Doubles Prize to $50,000

OpenAI doubles its biosafety jailbreak reward to $50K and turns a one-time bounty into a permanent program, as GPT-5.6 earns a 'High' bio-risk rating across all three model tiers for the first time.

·
·
OpenAI Makes Its GPT-5.6 Bio Bounty Permanent and Doubles Prize to $50,000
AuthorOpenAI
Read2 min
  • $50K prize: OpenAI doubles its bio jailbreak reward from $25K to $50K and makes the program permanent, covering GPT-5.6 and beyond.
  • The challenge: Find one universal prompt that defeats all five predefined biosafety questions in a single clean chat session without triggering moderation.
  • GPT-5.6 rated High bio-risk: All three GPT-5.6 models (Sol, Terra, Luna) carry a "High" Biological and Chemical risk rating -- the first time every tier of a model family hits this level.
  • Invite-only with NDA: Researchers apply via a rolling process; all findings are confidential and covered by NDA.
  • GPT-5.5 scope ends July 27: After that date, only GPT-5.6 will be in scope for the ongoing program.
  • Industry-wide pressure: OpenAI, Google DeepMind, Anthropic, and Meta are all racing to formalize biosafety evaluations as frontier models approach expert-level biological knowledge.

OpenAI has upgraded its Bio Bug Bounty from a time-limited experiment into a permanent, ongoing private program -- and doubled the prize money to $50,000. The move is not a routine security update. It is a direct response to a new generation of frontier models that OpenAI itself classifies as posing a meaningfully higher biological risk than anything it has shipped before.

From one-off to permanent fixture

OpenAI is evolving its GPT-5.5 Bio Bug Bounty into an ongoing private program -- the OpenAI Bio Bounty Program -- which will remain focused on universal jailbreaks that can defeat its predefined biosafety challenge against frontier models, starting with GPT-5.6 and going forward. The original program was a bounded experiment. This one has no end date.

The reward for a universal jailbreak has been raised from $25,000 to $50,000 for both GPT-5.6 and GPT-5.5. Smaller awards may be granted for partial wins at OpenAI's discretion. GPT-5.5 testing ends July 27, 2026, after which only GPT-5.6 will be in scope.

What the challenge actually asks you to do

A "universal jailbreak" in this context means something very specific. The challenge is to identify one universal jailbreaking prompt that can successfully answer all five bio safety questions from a clean chat session without prompting moderation. You cannot brute-force it question by question -- a single prompt has to defeat all five guardrails in one shot.

The five questions themselves are not public, which is intentional. ChatGPT's safety mechanisms are normally supposed to detect and prevent such attempts -- for example, if a user asks for the detailed manufacturing process of a biological weapon, the model would very likely refuse and explain that the information is dangerous. The bounty tests whether those refusals are truly robust or whether a clever enough prompt can route around all of them at once.

Keep reading

Don't miss what's next in AI

Join 300,000+ engineers and researchers who get the signal, not the noise. Create a free account to read the rest of this story.

  • Full access to in-depth AI research breakdowns
  • Be the first to know what's trending before it hits mainstream
  • Daily curated papers, repos, and industry moves