OpenAI Puts $25,000 on Finding a Bio Jailbreak in GPT-5.5 — 5 Questions, Codex Desktop Only
OpenAI launched a Bio Bug Bounty for GPT-5.5 on April 23, the same day the model went live. The program offers $25,000 to the first researcher who finds a universal jailbreak prompt that clears all five biosafety questions from a clean chat session, with smaller discretionary awards for partial breaks.
The scope is narrow by design: GPT-5.5 accessed through Codex Desktop only. Testing opens April 28 and closes July 27, 2026. Applicants must have an existing ChatGPT account, sign an NDA, and be accepted into the invite-only platform. OpenAI said it will extend invitations to a vetted list of trusted bio red-teamers while reviewing new applications on a rolling basis through June 22.
Why It Matters
The bounty is an operational signal, not a PR exercise. GPT-5.5’s system card classifies the model as High capability in the Biological and Chemical domain under OpenAI’s Preparedness Framework — the designation reserved for models OpenAI believes are at or near the threshold for meaningfully assisting in the creation of a severe biological threat. Under the Framework, High bio capability triggers a mandatory safeguards package: specialized safety training, system-level content screening on 100% of production traffic, and account-level enforcement.
Every model in the GPT-5 family since the original GPT-5 has carried this designation. GPT-5.5 continues that lineage.
Challenge Structure
The GPT-5 Bio Bug Bounty launched in September 2025 required a universal jailbreak that cleared ten bio/chem safety questions and offered $25,000 plus a separate $10,000 prize for multi-prompt answers. The GPT-5.5 bounty is smaller in scope: five questions only, no tiered reward structure beyond the primary prize, no chemistry questions listed in the scope.
That narrowing reflects the shift from a broad bio/chem evaluation to one targeting biological risk specifically in the context of a Codex-integrated model. GPT-5.5 is OpenAI’s most agentic deployment to date: it ships with 82.0% Terminal-Bench 2.0 accuracy under the Codex scaffold and operates as a background desktop agent with file system and application access. A bio jailbreak in that context is not an abstract policy question — it is a pipeline from prompt to execution.
Access and Disclosure
The program is invitation-and-application only. Accepted researchers are onboarded to a dedicated bio bounty platform. All prompts, completions, findings, and communications are covered by NDA, which limits public disclosure of any discovered vulnerabilities. OpenAI retains the findings and determines whether partial wins qualify for discretionary awards at its sole discretion.
The program runs concurrently with OpenAI’s broader Safety Bug Bounty — launched March 2026 — which covers agentic misuse, MCP prompt injection, and account integrity. Bio-specific jailbreaks are explicitly out of scope for that program and ring-fenced into targeted campaigns like this one.
Context
OpenAI’s approach to bio risk has hardened across the GPT-5 generation. GPT-5.3-Codex was the first model the company classified as High in Cybersecurity; bio/chem has been treated as High since ChatGPT Agent. GPT-5.5 does not appear to cross a new threshold — it continues to sit at High bio capability — but the Codex Desktop integration creates a materially different deployment surface than a chat interface. Running a bug bounty against that specific surface, with testing beginning four days after launch, suggests internal red-teaming left questions that external researchers are now being paid to answer.