bounty · online
Mozilla 0DIN GenAI Bug Bounty
When it actually closes
No end date or time zone is given anywhere. It is an ongoing program. The policy says the terms "are subject to change" and that researchers already engaged will be notified.
Prizes
$15,000 max single award
This is an uncapped, per-bug, discretionary bounty. There is no prize pool: $15,000 is the largest single bounty. Policy: rewards "range from $500 to $15,000," and "as a generality" Low is up to $500, Medium up to $2,500, High up to $5,000 and Severe up to $15,000. Scope page, model categories: Prompt Extraction $100, Guardrail Jailbreak $500-$1,000, Interpreter Jailbreak $2,500, Content Manipulation $5,000, Weights and Layers Disclosure $15,000.
Model — Prompt Extraction
cash
$100
Marked N/A for almost all in-scope models in practice
Model — Guardrail Jailbreak
cash
$1,000
Range $500-$1,000; must be demonstrated across at least two testing categories
Model — Interpreter Jailbreak
cash
$2,500
Model — Content Manipulation
cash
$5,000
Model — Weights and Layers Disclosure
cash
$15,000
App — Read Violation
cash
$5,000
Range $1,000-$5,000; 11 in-scope apps
App — Write Violation
cash
$7,500
Range $2,500-$7,500
App — Execute Violation
cash
$15,000
Range $5,000-$15,000
Eligibility
Individuals: eligible
You must be the age of majority to be eligible to participate in and receive payment from this program in your jurisdiction
Checked for one adult entering alone from Nevada, USA. Rules can differ by country, so read the rule quoted here for where you live.
Entry cost
Free to enter
Payout
unknown
The public pages do not name the payment rail (no wire, PayPal or crypto mentioned). Payment is sent "within 30 days of reaching a contractual agreement," and the site says bounties are paid before public disclosure. KYC is required: a government-issued photo ID, plus an IRS W-9 for US researchers.
Rights — what you give up
entrant-keeps
Submissions fall under Mozilla's Website & Communications Terms of Use. That grants Mozilla a nonexclusive, royalty-free, worldwide, sublicensable license to use the submission. It is a license, not an ownership transfer, and it is governed by California law with venue in Santa Clara County.
Gotchas
- Prompt Extraction ($100) is marked N/A for almost all of the 49 in-scope models, including every Anthropic, Google, OpenAI (except GPT 5.6 Luna) and most Grok models. In practice the cheapest tier is mostly unavailable.
- Official pages disagree with each other. The scope page lists Prompt Extraction at $100 and Guardrail Jailbreak at $500-$1,000. The policy says Low is 'up to $500' and rewards 'range from $500'.
- Guardrail jailbreaks must be demonstrated across at least two different testing categories.
- Illicit-substance jailbreaks are not accepted on any Anthropic model. Copyright and illicit-substance bypasses are ineligible on Amazon Nova, NVIDIA NeMo Megatron and Grok 4.20/4.5/4.6/4.7.