Vercel: $1M Hacker Challenge for Sandbox Escape

What shipped? Vercel launched a public HackerOne challenge offering up to $1,000,000 in bounties for researchers who can break out of a Vercel Sandbox.

What changed? The two-week program runs publicly on HackerOne. Researchers get a dedicated Sandbox environment and are scored on the severity of their escape — RCE on the host, access to another customer's sandbox, or breaking the network boundary. Bounties scale from tens of thousands up to the full $1M for a full host escape chain.

This follows Vercel Sandbox's GA last week and signals serious investment in the security posture of ephemeral compute. Sandbox runs untrusted code on every deploy preview, every edge function, and every AI agent workflow — the attack surface is wide, and Vercel is making it public to find the gaps before attackers do.

Why a builder cares? If you deploy preview branches or run AI agents on Vercel, your code executes inside these sandboxes. This challenge is the audit. Watch the findings — they'll reveal the actual attack surface of serverless sandboxing.