Meta opens Muse bug bounty worth up to $300,000 as robot tests expose AI safety gaps
Meta opened its Muse agent bug bounty to the public on 25 September, offering up to $300,000 for valid reports and up to $130,000 for prompt injection attempts that affect one user.

Meta opened its Muse agent bug bounty to the public on 25 September, according to a post on Meta AI Research. The program pays up to $300,000 for valid reports. Successful prompt injection attempts that affect one user bring up to $130,000.
The company said it hardened Muse through dogfooding, agentic red teaming and issues found by security researchers in a private bug bounty program. Muse is a personal agent. It runs in what Meta calls an isolated cell: a systemd-nspawn runtime container with its own root filesystem, a virtual network interface, filtered system calls, and limited kernel capabilities. Root inside the cell maps to an unprivileged host user, so runtime cell root is not host root. Meta's post is the most detailed public account of safety engineering in the dossier. It arrives alongside research that shows how hard that engineering is to validate.
On 27 September, The Decoder reported that researchers from Stanford and Caltech built HomeBody, a system that lets a Unitree G1 robot autonomously navigate an unfamiliar kitchen, tidy up and fetch items from drawers. HomeBody drops the typical trained control layer between the language model and the robot. A swappable vision-language model, here GPT Astra, calls directly into a skill library for grasping, navigating and opening drawers. The robot explores the room first, builds a digital twin in Nvidia's Isaac Sim, and logs objects and locations in spatial memory. That lets it find items after they leave its field of view. For tasks like "clean up the kitchen," the language model plans each step and self-corrects on errors. The Decoder listed limitations including Astra's latency, overheating finger servos and high compute costs. The code is on GitHub. Earlier benchmarks showed Astra's greatly improved spatial reasoning, the outlet noted, while another flagged safety issues when Astra controls a robot.
The same day, The Decoder reported that Boris Power, OpenAI's Head of Applied Research, said 80 to 90 percent of the company's research goes toward GPT 7, GPT 8 and beyond because that is where "most of the value" comes from. Incremental updates within a generation, such as going from GPT 5.1 to 5.2, come from specialized training data but are intentionally short-term bets, Power said. He described the main challenge with today's assistants as onboarding rather than model quality. Most ChatGPT users, he said, do not know what they can do with AI.
Those comments frame a gap that the dossier's safety material keeps circling. Meta says Muse can and will still make mistakes, and that its system assumes the agent may be under attack. OpenAI says the leap comes with a new model generation. Neither claim is a guarantee. The HomeBody work shows the failure modes are physical as well as digital.
Elsewhere, Tom's Hardware reported on 27 September that Flock is seeking to have a security researcher's map of its cameras taken down. The researcher, Joshua Michael, found an unauthenticated flaw that gave him an access token without login credentials, according to The Intercept, and used it to query ArcGIS, a third-party mapping layer Flock uses, to retrieve a database of Flock devices in November 2025. The resulting Flock Surveillance Map lists 335,701 camera locations. Flock says its cloud platform has never experienced a data breach. Michael told The Intercept the company made that announcement after he pulled the device database.
Sources
4- 01We Built Safety into MuseEN
- 02Researchers plug GPT-6 Astra directly into a robot and let it clean up an unfamiliar kitchenEN
- 03OpenAI says 80 to 90 percent of its research already targets GPT 7 and beyondEN
- 04Flock seeks to have security researchers' map of Flock cameras taken downEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.