Featured image of post Million-Dollar Bounties: A Global Inventory of Unsolved Prizes, Bug Bounties, and Zero-Day Markets

Million-Dollar Bounties: A Global Inventory of Unsolved Prizes, Bug Bounties, and Zero-Day Markets

Starting from the rumor that 'Claude solved Navier-Stokes' — three-vote adversarial fact-check plus Terence Tao's denial rule it a misattribution; the real story is OpenAI using ~10,000 agents and $15M to find an NS singularity, Lean-formalized but un-awarded by Clay pending review. Then a full inventory, as of September 2026, of every field still paying bounties: Millennium Prizes, security bug bounties, the zero-day grey market, AI competitions, crypto bounties, math & science open-problem prizes, incentive grand challenges, and hardware/CTF. 86 sources reviewed.

First, the rumor that “Claude solved Navier-Stokes”

You’ve probably seen this one making the rounds: Anthropic’s Claude solved the million-dollar Millennium Prize problem — the Navier-Stokes equations — with a proof submitted for expert review.

I dispatched three independent fact-checking agents to refute it (defaulting to skeptical, only flipping to “confirmed” if they found a primary source from Anthropic itself or the Clay Mathematics Institute). The vote was unanimous: REFUTED — a misattribution. Terence Tao (Fields Medalist) also publicly denied it on Mathstodon.

But the story is more interesting than a simple debunk, because there genuinely was major news two days ago (2026-09-08) that got distorted in the telling. The truth splits into three threads:

First, the real claimant is OpenAI, not Claude. On 2026-09-08, OpenAI announced that roughly 10,000 autonomous AI agents, running on an unreleased internal model, had found a “singularity/blowup” in the 3D Navier-Stokes equations — a point where fluid velocity tends toward infinity. This matches the Clay Millennium version (3D, unbounded, smooth forcing term). It cost about $15 million and reportedly produced ~130 billion tokens. Crucially, the proof was formalized in Lean (via GPT-6, an additional 17 hours) — which gives it the credibility of “a real proof, not just bragging.” But Quanta’s reporting carries the caveat “if the result holds up to further scrutiny” — the Clay Mathematics Institute has not awarded the prize, the $1 million is unpaid, and acceptance is pending review. By Clay’s own rules, a proof must first be published in a refereed journal, then survive at least two years of scrutiny and be accepted; Clay does not accept direct submissions. In other words, even if it were submitted today, the earliest resolution would be around 2028.

Second, the “Claude solved it” misattribution comes from something an Anthropic employee and an NYU professor did with Claude. Anthropic employee Levent Alpöge and NYU professor Tristan Buckmaster used Claude and Codex on a related but different Euler equation problem for nearly a year, achieved a breakthrough on 2026-08-15, and published their Euler result the night before OpenAI’s Navier-Stokes announcement. OpenAI had heard the rumor that “some major open problem had been solved,” and on that basis launched its Navier-Stokes push on 09-01, completing it on 09-05. The more delicate part: OpenAI offered to publish simultaneously but excluded Alpöge from authorship, and made the rare public statement that it “cannot rule out that de-identified data from their product use was used to improve our models” — i.e., possible training-data leakage, a kind of scoop. Simon Willison pressed OpenAI on whether their model was trained on Buckmaster/Alpöge’s Codex sessions; he said, “I did not get an answer.”

Third, the specific source of the rumor you heard. X user Andrew Curran posted a “prediction post” predicting that Anthropic/Claude had already solved Navier-Stokes existence and smoothness, which then spread as news; Reddit’s r/singularity had an “Anthropic possibly tackles its first Millennium Prize Problem” discussion. There was also a fictional blog post on the DEV community (using GPT-5.4 Pro, not Claude) muddying the waters. On the Clay Institute’s page, Navier-Stokes still hangs in the “unsolved” list. Anthropic’s only public research touching math is about the Riemann zeta function — nowhere near Navier-Stokes.

So the one-line summary of this rumor: “the proof is under expert review” happens to be true (referring to OpenAI’s still-pending proof), but “Claude solved it” is a misattribution — the real story is OpenAI burning $15 million with a swarm of agents to find a singularity, which Clay has not yet accepted.

Simon Willison had a sharp analogy that ties this rumor to the rest of this post: in security, he said, “just a rumour of a bug is enough to find a security exploit” — and now it’s the same in math; “knowing a solution exists” itself becomes a kind of exploit. OpenAI, hearing the rumor that “a major problem has been solved,” reproduced a Navier-Stokes singularity proof within days.

Full table of bounty avenues (as of September 2026)

A preview table for the full picture first, with each domain expanded below. Note the “nature” column varies a lot: some are in-progress prize pools (not fully paid), some are single payouts already made, some are grey-market offers, and some are platform annual totals — you can’t just compare the numbers head to head.

DomainRepresentative program/platformTop amountNature / notes
Millennium PrizeClay Math Institute, 7 problems$1M eachOpen problem; requires journal pub + ~2yr review; only Poincaré solved (Perelman declined prize)
Bug bountyWormhole (via Immunefi)$10MSingle payout, largest ever
Apple Security Bounty$2M–5MZero-click chains; upgraded 2025-10
Google (annual)$17M/yr2025 annual total; $81.6M cumulative
HackerOne platform$81M/yrPlatform annual total; 6 hackers each cleared $1M, median only $500
MakerDAO$10MWeb3 program cap (offered, not necessarily collected)
GitHub(cut 50%–88% in 2026-07)AI junk reports flooded queue; top bugs moved to VIP channel
Zero-day grey market (offers)Crowdfense (iOS zero-click full chain)$5M–7MHighest offer on the list; $30M fund
Operation Zero$20MNation-state buyer pricing (iOS/Android full chain)
Zerodium(shut down 2025-01)Veteran broker, defunct; price list only on Wayback
Crypto bountyImmunefi (cumulative)$100M+Three-year cumulative payouts
Aurora$6MSingle payout
Ethereum Foundation$1MRaised from $250k in 2025-03
Bitcoin Core~€50No formal high-value bounty; responsible disclosure
AI / ML competitionAIMO Prize$5MGet AI to IMO level
ARC Prize 2026$2M total$275k grand prize; open-source required
Konwinski Prize$1MSolve 90% of SWE-bench
Kaggle (annual)$16M+/yr$25k–$100k per competition
Math / science open problemBeal Conjecture$1MUnsolved; AMS-administered
Collatz Conjecture~$1.1M (120M JPY)Unsolved 80+ years
Wolfram Rule 30$30kThree questions, $10k each
Incentive grand challengeXPRIZE Water Scarcity$119MIn progress, largest science bounty today (desalination)
XPRIZE Healthspan$101MIn progress; 10 finalists each got $1M upfront
XPRIZE Carbon Removal$100MAwarded (2025, Mati Carbon)
DARPA AIxCC$8.5M finalsAwarded; champion Team Atlanta $4M
Hutter Prizelong-term, smallCompress enwik9; still paying 2024
Hardware / CTFPwn2Own Berlin 2026$1.298MTotal; DEVCORE $505k + Master of Pwn
Google Linux kernel$91,337Leet-speak easter-egg prices; extended indefinitely
Google OSS-Fuzz$30k/project13,000+ bugs found
Intel$100k–250kHardware/microcode; via Intigriti
DEF CON xTechSearch$100kTechnical-concept prize, up to 6 winners

The Millennium Prize Problems: seven problems, $1 million each

The Clay Mathematics Institute set out seven Millennium Prize Problems in 2000, each worth $1 million for a solution. As of September 2026, only one has been solved.

  • Poincaré Conjecture — solved. Perelman proved it in 2002-2003 using Ricci flow with surgery. He declined the Fields Medal in 2006, and in July 2010 declined the $1 million, on the grounds that Hamilton’s contribution was equally important. This remains the only solved Millennium problem.
  • Navier-Stokes existence and smoothness — open (the subject of the rumor above). OpenAI claims a singularity proof but it has not been accepted.
  • BSD conjecture, Hodge conjecture, P vs NP, Riemann hypothesis, Yang-Mills existence and mass gap — all open, each with a $1 million bounty.

Note that Clay’s awarding rules are stringent: a proof must be published in a refereed journal, survive at least two years of review, and be accepted; Clay does not accept direct submissions. So even if someone produces a first-rate proof tomorrow, the earliest payout is around 2028. Clay separately awards the “Clay Research Award,” which honors already-completed excellent work (not the same as the Millennium Prize) — in 2026 it went to Orponen et al. (Furstenberg/Kakeya) and to Hani and Deng (Boltzmann equation).

Security bug bounties: white-hats take home hundreds of millions a year

This is the most systematic and best-funded category of bounty. A few of the most striking figures (as of September 2026):

  • Wormhole $10 million — the largest single bug bounty ever paid. White-hat Satya0x reported an uninitialized-proxy vulnerability in a cross-chain bridge (which could enable unlimited token minting) via Immunefi and took home $10 million, confirmed by multiple outlets.
  • MakerDAO $10 million — the largest Web3 bounty program cap (note: “offered cap,” not necessarily collected).
  • Apple Security Bounty — upgraded in October 2025: zero-click exploit chains $2 million, up to $5 million with bonuses.
  • Google — paid out $17 million in 2025 (vs. $12 million in 2024), cumulative over $81.6 million; Android Pixel full-chain remote code execution up to $1.5 million.
  • HackerOne platform — paid $81 million over the past year, with six hackers each clearing a million, but a median of only $500 (extreme inequality).
  • Meta — over $4 million in 2025, over $25 million cumulative over 15 years.
  • Immunefi — a $3 million single payout in 2025 (researcher ily2), though the all-time record remains Wormhole’s $10 million.

Two trends worth noting. First, GitHub cut public bounties by 50% to 88% in July 2026, moving top-tier bugs to a VIP channel, on the grounds that AI-generated junk reports were flooding the queue and driving up triage costs — i.e., AI reporting bugs is itself depressing human white-hat payouts. Second, OpenAI’s own bounty figures conflict (original cap $20k, Bugcrowd page shows up to $100k); it also has Bio and Safety sub-programs.

On the platform side, HackerOne, Bugcrowd, Intigriti (third-largest globally, but no disclosed figures), and Synack (invite-only, average over $2,500/vuln, higher than the first two) are the big four. Microsoft pays up to $250,000 for high-impact bugs; Cloudflare up to $15,000 for critical bugs (part of the CISA pledge).

The zero-day grey market: brokers’ public price lists

Unlike the “white-hat reports to vendor” model above, this is a grey market of cash-for-goods — zero-day exploit brokers publish price lists by vulnerability type, with buyers typically intelligence agencies and militaries. As of September 2026, the dominant player is Crowdfense (a $30 million fund):

  • iOS zero-click full chain (iMessage): $5M–$7M — the highest tier on the entire list.
  • Android zero-click full chain: $5M.
  • WhatsApp / iMessage zero-days: $3M–$5M each.
  • Chrome / Safari mobile full chains: $2M–$3.5M; individual RCE/SBX components $500k each.
  • Windows / macOS / Linux: zero-click full chain up to $1M; desktop Chrome full chain $1.5M.
  • Enterprise / virtualization (Hyper-V, ESXi, Apache, IIS, WordPress): up to $500k; Exchange $250k.

The other veteran broker, Zerodium, shut down in January 2025 (its site was replaced with a PGP-key page; the price list is only accessible via the Wayback Machine). On its last chart, iOS zero-click topped $2 million, and in 2019 it raised Android to $2.5 million — the first time Android priced higher than iOS. There’s also a Russian broker, Operation Zero, offering up to $20 million for iOS/Android full chains — reflecting nation-state buyer pricing. Over the past decade, grey-market zero-day prices have inflated ~44% annually, driven by two factors: platforms getting harder to crack, and intelligence-agency demand growing.

One comparison is telling: the same iOS zero-click full-chain vulnerability, handed to Apple (legally) yields up to $5 million; handed to Crowdfense (grey market) yields $7 million; handed to Operation Zero (nation-state buyer) can reach $20 million. Who you sell to determines what it’s worth.

Crypto bounties: Immunefi has paid out over $100 million

Web3 bounties are dominated by Immunefi, which by June 2024 had paid out over $100 million cumulative (about three years). The big ones:

  • Wormhole $10 million (the one above, the largest single Web3 payout).
  • Aurora $6 million (an EVM-layer bug on NEAR that could have led to over 200 million ETH being stolen, September 2022).
  • Ethereum Foundation — raised from $250k to $1 million in March 2025, covering consensus and client bugs.
  • Kamino Finance (largest on Solana) $1.5 million program cap.
  • Polygon $250k, Avalanche $100k (paid in AVAX).
  • Bitcoin Core has no formal high-value bounty, relying on responsible disclosure, with rewards as low as ~€50.

A trend worth watching: Forbes (2025) noted that zero-knowledge proofs (ZK) could fix trust issues in bounty programs — no large independent ZK bounty program exists yet, but it may be a new direction.

AI and ML competitions: turning benchmarks into prize money

This category’s hallmark: the bounty is pegged to a public benchmark — whoever first pushes AI past a line takes the money.

  • AIMO Prize (AI Math Olympiad) $5 million grand prize — getting AI to International Math Olympiad level. Runs on Kaggle, with Tao involved. Two progress prizes awarded; the third is launched.
  • ARC Prize (2026) $2 million total — $275k grand prize. In 2025, NVARC won $25k at 24.03%. All solutions must be open-source.
  • Konwinski Prize $1 million — AI solves 90% of fresh GitHub Issues on SWE-bench to claim it; on Kaggle, winner announced in 2026.
  • FrontierMath $10,000 pool — Epoch AI’s math benchmark, held at Cambridge in March 2025. Its bigger story is the OpenAI secret-funding controversy.
  • Kaggle annual — over $16 million total in 2025, typically $25k–$100k per competition.
  • Completed competitions: IBM Watson AI XPRIZE (2016-2021, $5M, winner Zzapp Malaria for anti-malaria AI), Global Learning XPRIZE ($15M, 2019, two winners Kitkit School and Onebillion).

Note the distinction: SWE-bench Verified, LiveCodeBench and the like are pure benchmarks with no bounty — their value is reputation and model marketing; the cash layer is the Konwinski Prize hung on top of them.

Math & science open-problem prizes: from Erdős’s hundreds to XPRIZE’s hundreds of millions

Beyond the Millennium problems, there’s a wide range of open-problem prizes with cash attached.

Math, smaller scale:

  • Beal Conjecture $1 million — funded by D. Andrew Beal, administered by the AMS, raised from $5,000 to $1 million in 2013, unsolved.
  • Collatz Conjecture 120 million JPY (~$1.1 million) — funded by Bakuage Co. in 2021; Erdős previously offered $500. Unsolved for 80+ years.
  • Wolfram Rule 30 Prize $30,000 — posed by Stephen Wolfram in 2019, three questions about Rule 30’s center column at $10k each, unsolved.
  • Goldbach Conjecture $1 million (Faber and Faber, 2000; expired 2002; problem unsolved, prize void).
  • Erdős and Conway’s informal bounties are still active (mostly $500–$5,000): Erdős’s $5,000 “happy ending” problem, his $500 Collatz, Conway’s $1,000 thrackle problem. The Erdős prime-gap problem Tao and Polymath solved in 2014 carried a $10,000 bounty, paid by Graham after Erdős’s death.
  • Riemann hypothesis has no independent bounty beyond Clay’s $1 million.

Science grand prizes (the biggest category — the incentive challenges below): XPRIZE Carbon Removal $100 million (awarded 2025, winner Mati Carbon, largest environmental prize ever), XPRIZE Healthspan $101 million (in progress), XPRIZE Water Scarcity $119 million (in progress, see below), Breakthrough Prize in math $3 million/laureate (rewards completed work, not open problems; 2025 to Gaitsgory for geometric Langlands), Google Lunar XPRIZE $30 million (no grand winner before 2018; SpaceIL took a $5M Moonshot award).

Incentive challenges: not the same as bug bounties

An incentive grand challenge’s model is “set a goal humans haven’t achieved, pay whoever hits it first” — entirely different from “find a bug, get paid by the vendor.” I specifically supplemented the research on this category because it’s the easiest to conflate with bug bounties.

  • XPRIZE Water Scarcity $119 million — a desalination competition, both tracks requiring daily output of 1 million liters of drinking water; final testing deadline March 20, 2026. The largest in-progress science bounty today.
  • XPRIZE Healthspan $101 million — the largest XPRIZE prize pool ever; 10 finalist teams each got $1 million upfront (2025), grand prize around 2026-2027, plus a $10M FSHD add-on.
  • DARPA AI Cyber Challenge (AIxCC) — finals pool $8.5 million (champion Team Atlanta / Georgia Tech $4M, runner-up Trail of Bits $3M, third Theori $1.5M); total project investment starting around $20 million. Awarded at DEF CON 33 in 2025; the task was AI autonomously finding and fixing bugs in open-source software, with winning systems open-sourced. The largest nation-state “AI for defense” bounty today.
  • NASA Centennial Challenges — 3D-Printed Habitat awarded ~$2.06 million total (one team $700k at a stage, completed); Sample Return Robot $1.5 million total (milestones still being awarded in 2026).
  • HeroX / InnoCentive — crowdsourced innovation platforms, single challenges from $1,000 to over $3.1 million, InnoCentive averaging ~$20k, HeroX taking an 18% success fee.
  • Hutter Prize — compressing enwik9 (1GB of English Wikipedia), paid by compression-rate improvement, open long-term; the underlying thesis is “text compression ability ≈ general intelligence.” Small payouts were still being awarded in 2024.
  • Other active XPRIZEs: Wildfire $11M, Quantum Applications $5M, Future Vision $3.5M; Evolution 2.0 Prize $10 million (via HeroX, digital simulation of the origin of life, status unclear).

Hardware and misc: Pwn2Own and CTF

  • Pwn2Own Berlin 2026 — $1.298 million total, 47 zero-days, DEVCORE broke 4 Microsoft products winning $505k and Master of Pwn. Covered browsers, virtualization, servers, automotive.
  • Pwn2Own Berlin 2025 — $1.132 million total, Manfred Paul took Master of Pwn with $202.5k (incl. $50k Firefox).
  • Pwn2Own Automotive 2024 — focused on automotive IVI systems, APIs, and zero-days; a Tesla bug earned $200k.
  • ZDI bounty (points-based) — run by Trend Micro, $2,000–$25,000 per bug, 20th anniversary in 2025.
  • Google Linux kernel bounty — patched $31,337, zero-day up to $50,337, Linux + Kubernetes up to $91,337 (all leet-speak easter eggs), extended indefinitely in 2025.
  • Google OSS-Fuzz — continuous fuzzing of open-source software, up to $30k per project, 13,000+ bugs found.
  • Intel bounty — hardware/microcode bugs, via Intigriti, some sources say up to $100k–$250k. AMD also runs via Intigriti, amount undisclosed.
  • Hack the Pentagon — U.S. DoD, launched 2016, assisted by Synack, HackerOne, Bugcrowd, some rounds 500+ hackers.
  • DEF CON CTF — the main CTF doesn’t publish large cash prizes, running on reputation and black badges; CMU’s PPP team won their fourth straight and ninth overall in 2025. But DEF CON xTechSearch (U.S. Army) gives a $100,000 technical-concept prize, up to 6 winners.

A “biggest bounties” ranking (as of September 2026)

Roughly sorted by offered/paid amount (note the different natures: in-progress pools, paid single payouts, grey-market offers):

  1. XPRIZE Water Scarcity — $119 million (in-progress pool)
  2. XPRIZE Carbon Removal — $100 million (awarded)
  3. XPRIZE Healthspan — $101 million (in progress)
  4. Operation Zero (iOS/Android full chain) — $20 million (grey-market offer)
  5. HackerOne platform annual — $81 million (platform total, not single)
  6. Google annual bug bounty — $17 million (2025 annual total)
  7. DARPA AIxCC — finals $8.5 million pool (champion $4M)
  8. Wormhole / MakerDAO — $10 million (single paid / program cap)
  9. Immunefi cumulative — over $100 million (three-year total)
  10. Crowdfense iOS zero-click full chain — $5M–$7M (grey-market offer)
  11. AIMO Prize — $5 million (AI competition grand prize)
  12. Clay Millennium problems — $1 million each (7 problems, 1 solved)
  13. Collatz Conjecture — ~$1.1 million (120 million JPY)

(HackerOne’s $81M and Google’s $17M are “platform/vendor annual totals,” not single payouts; included in the ranking only to convey the scale of the white-hat market.)

Key takeaways

  1. Don’t take rumor for fact. “Claude solved Navier-Stokes” was ruled a misattribution by a unanimous three-vote check; the real story is OpenAI using 10,000 agents and $15 million to find a singularity, Lean-formalized but un-awarded by Clay and pending ~two years of review. Tao publicly denied it; Clay’s page still lists it “unsolved.”
  2. Who you sell a vuln to determines its price. iOS zero-click full chain: handed to Apple legally yields up to $5M, to Crowdfense’s grey market $7M, to Operation Zero’s nation-state buyers up to $20M.
  3. AI is squeezing the bounty market from both ends. On one side, AI-generated reports made GitHub cut public bounties 50%–88%; on the other, DARPA’s AIxCC spends an $8.5M finals pool to bounty “letting AI find bugs itself.”
  4. Science grand prizes dwarf math prizes. Millennium problems at $1M each are already top-tier, but XPRIZEs run into the hundreds of millions (water $119M, carbon $100M, healthspan $101M). AI competitions are rising too (AIMO $5M, ARC $2M).
  5. “Knowing a solution exists” itself becomes an exploit. In Simon Willison’s words: in security, just a rumor of a bug is enough to find an exploit; now it’s the same in math — OpenAI, hearing the rumor that “a major problem has been solved,” reproduced a Navier-Stokes singularity proof within days.

Sources

This inventory reviewed 86 sources; key primary sources: