Meta Opens Muse Bug Bounty With $300,000 Top Award as Flock Faces Camera Map Complaint
Meta has opened its Muse agent bug bounty to the public, offering up to $300,000 for valid reports, including up to $130,000 for a single successful prompt injection, according to a research blog published on 25 September. Two days later, Flock asked for a map of 335,701 of its cameras to be taken offline.

Meta published the terms on 25 September, and the numbers are the story. The company pays up to $300,000 for valid reports. Up to $130,000 of that is reserved for a prompt injection that affects one user. Meta says the program was previously private, and that the move follows agentic red teaming and findings from real adversarial scenarios.
Meta AI Research wrote the post. It describes an architecture built on one assumption: the agent will be attacked through the data it reads. The agent harness runs in a systemd-nspawn container where root maps to an unprivileged host user. It gets its own Debian root filesystem and a filtered syscall set that blocks io_uring, CAP_SYS_PTRACE and CAP_NET_ADMIN. Safety classifiers and privileged connector workers sit outside that cell, so an attacker cannot switch them off.
That is a design claim, not a result. Meta states plainly that Muse can and will still make mistakes, though it expects them to be less frequent and less damaging. Testing has so far relied on dogfooding, red teaming and the private bounty. That is thin evidence for an agent that Meta says has been handed inboxes, calendars and a shell since early 2026.
The contrast with events the same weekend is hard to miss.
On 27 September, Tom's Hardware reported that Flock has filed a trademark infringement complaint seeking to have a security researcher's map of its cameras taken down. The site lists 335,701 camera locations. According to The Intercept, cited by Tom's Hardware, researcher Joshua Michael found an unauthenticated flaw in Flock's website that returned an access token without login credentials. He then queried ArcGIS, the third-party mapping layer Flock uses, to pull a device database in November 2025.
Michael told The Intercept he reported the flaw on 13 November 2025. All testing was strictly non-intrusive, he wrote, limited to open unauthenticated endpoints. Tom's Hardware reports that Flock did not reply to his first message and took two more attempts before a representative responded, saying the findings were being triaged internally. Michael says the company still has not replied. Flock fixed the vulnerability in January, after he published, but the database had already been exfiltrated.
The company says Flock Safety's cloud platform has never experienced a data breach. Michael disputes that, telling The Intercept the statement came after he pulled the device database.
His framing is blunt: either the company knew and chose not to disclose it, or it did not detect the exfiltration at all. The first is a transparency failure, he said, the second a detection failure with national security implications. Tom's Hardware also notes earlier findings that Flock cameras stored encryption keys on the device, allowing extraction of more than 27,000 clips and showing 1.6 million images captured over 21 days, plus cases of officers misusing the system.
Both stories are about the same gap: what evaluation actually measures. Meta's bounty prices prompt injection at up to $130,000 for one affected user, a figure that implies the company knows a single bypass is plausible. Flock's case suggests the harder problem is not building a defence but noticing when it has already been passed.
Elsewhere the evaluation debate is moving faster than the deployments. The Decoder reported on 27 September that Stanford and Caltech researchers built HomeBody, which plugs GPT-6 Astra directly into a Unitree G1 robot, with no trained control layer between model and hardware. The robot explores an unfamiliar kitchen, builds a digital twin in Nvidia's Isaac Sim and self-corrects on errors. The listed limitations include Astra's latency, overheating finger servos and high compute costs.
On the same day, The Decoder reported that Boris Power, OpenAI's Head of Applied Research, said 80 to 90 percent of the company's research now targets GPT 7, GPT 8 and beyond. Power called incremental updates like GPT 5.1 to 5.2 extremely shortsighted internally, though useful for iterating quickly. He also said the main obstacle for current assistants is onboarding, not model quality.
Read together, the three positions are not contradictory so much as sequential. Meta prices the failure it expects. Flock shows what an undetected failure costs. OpenAI is already spending most of its research on models it has not shipped, and on the assumption that each generation simply works better.
Sources
4- 01We Built Safety into MuseEN
- 02Flock seeks to have security researchers' map of Flock cameras taken downEN
- 03Researchers plug GPT-6 Astra directly into a robot and let it clean up an unfamiliar kitchenEN
- 04OpenAI says 80 to 90 percent of its research already targets GPT 7 and beyondEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.