A security researcher hacked into OpenAI's private repositories but received only a $6,500 bounty despite accessing sensitive data worth potentially hundreds of thousands on the black market. The hack exploited an out-of-scope Discourse forum, leading OpenAI to invoke scope rules to minimize the payout, a practice that discourages legitimate security research and fails to address how real attackers ignore such restrictions.