Twitter/X

Samuel Colvin notes that 72 hours after Pydantic (with Prefect and Hugging Face)…

Brief

Samuel Colvin notes that 72 hours after Pydantic (with Prefect and Hugging Face) posted a $10,000 bounty on hackmonty.com to break out of the Monty sandbox and read a secret file or environment variable, 'thousands' of attempts have found no vulnerability or secret, implying Monty may be genuinely secure or attackers/AIs are overestimated.

Source evidence

What's going on?

it's been 72hrs since the bounty on hacking monty increased to $10,000, and no one has found a vulnerability.

No one has found the secret. No one has found any security issue. Thousands of tries. Nothing found.

Either Monty is actually secure, or you and your AIs are not quite as all-powerful as you thought you were! (or both)

hackmonty.com

Pydantic (@pydantic)

Hack Monty is back. Together with @Prefect and @Huggingface, we're putting up a $10,000 bounty for anyone who can break out of the Monty sandbox and read the secret file or environment variable.

pydantic.dev/articles/hack-m…

Have fun. Break it harder.

— https://nitter.net/pydantic/status/2061357099808878835#m