OpenAI Bug Let Users Access Paid Models Without API Key

A researcher uncovered a serious vulnerability that bypassed OpenAI’s usual security safeguards and allowed unrestricted access to paid models without needing an API key or even an account. The flaw reportedly broke through both the sandbox isolation and authentication layers meant to protect internal systems and billing checks.

What Happened?

Security expert Oliver Fish discovered the issue, which he described as a sandbox escape connected to OpenAI’s internal “Responses API.” This internal interface, used for agent-based workflows, is supposed to be gated behind authentication and authorization steps. However, Fish claims it was possible to send requests through an internal endpoint and receive model responses without any identity verification or prior payment credentials.

OpenAI’s own developer documentation normally requires developers to generate an API key before accessing models. The researcher’s bug submission carried a title suggesting full access to internal responses without authentication—a claim that, if true, represents a serious lapse in access controls.

What We Know — and What We Don’t

Technical specifics are still sparse. Key unanswered questions remain about which models were exposed, how long the vulnerability persisted, and whether customer data was impacted. There is no proof yet that the flaw was exploited beyond Fisher’s private testing. No publicly released proof-of-concept code, endpoint details, or model names have been confirmed.

In acknowledgment of the discovery, OpenAI awarded Fish $300 through its bug bounty program. The amount stirred debate, as many consider it low for a vulnerability that potentially granted free access to OpenAI’s paid infrastructure. According to the company, the bounty tiers run from $200 for low-severity bugs up to $20,000 for exceptional severity—but OpenAI has not explained how the bug’s potential impact was evaluated in this case.

Why This Matters Now

A sandbox escape that also bypasses authentication essentially collapses the boundaries between internal services and public-facing APIs. It enables unauthorized usage, undermines trust, and could allow free or fraudulent usage of expensive brainpower models. For any cloud or AI service provider, this type of bug demands swift mitigation.

Security best practices suggest enforcing identity verification at every layer, not just at exposed APIs. Internal routing paths should block anonymous access and include rate-limiting and billing enforcement. Monitoring systems need to trigger alerts when requests lack a verified identity, even if they originate from internal services.

It remains unclear when the issue was fixed or whether logs show unauthorized access. OpenAI has not specified which services were affected or for how long. Meanwhile, users are being advised to vigilantly check billing statements and system logs. Rotating API keys is insufficient when the security bypass is server-side.

Analysis: This vulnerability reveals just how fragile the assumptions of internal security can be in overly complex AI systems. As more AI providers rely on internal APIs and microservices, the risk grows that a single overlooked internal path becomes a vector for major abuse. For customers and developers alike, the lesson is that trusted is not the same as secure—and zero-trust principles must get deeper.
What to watch: whether additional bugs like this are found, how OpenAI updates its internal tooling, and whether its bounty program adjusts pricing to better reflect the severity of attacks on core infrastructure.