Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Anthropic, Microsoft, and Google Paid Bug Bounties for AI Agent Vulnerabilities but Stayed Silent

Security researcher Aonan Guan exploited prompt injection vulnerabilities in AI agents from Anthropic, Google, and Microsoft through their GitHub Actions setups, successfully stealing API keys and tokens. Each company rewarded the findings with bug bounties—Anthropic paid $100, GitHub $500, and Google an undisclosed amount. Despite these payouts, none of the companies issued public advisories or disclosed the flaws to the broader community.

The Next Web
The Next Web