Home About Articles Contact
systems nominal · node heric.bz
Bug BountyVulnerability Research1PasswordVerification

The Million-Dollar Bit

1Password's CTF and the Verification Bottleneck

17 min read Vulnerability Research
The Million-Dollar Bit

1. The Bottleneck, Stated as a Contract

Sometime between late 2025 and early 2026, the organizing question of vulnerability research quietly inverted. Finding became a commodity. The bottleneck is now proving — and the 1Password Capture the Flag, read strictly from the outside, is the purest contract anyone has yet written around that single fact.

I argued the inversion first in The Machine That Reads Code. Discovery got cheap. A model walks a codebase file by file, framed as a CTF with forced structured output, and surfaces candidate after candidate at the price of API credits. What stayed expensive was the part that always mattered: turning a plausible finding into an artifact that runs. In a Firefox test, a model produced 22 candidate vulnerabilities cheaply and quickly. Working exploits emerged in only two cases — after roughly 350 attempts and about $4,000 in credits.

So here is a question. If you wanted to design a bounty that priced only the scarce half of that equation — the proving, never the finding — what would the contract look like?

It would look almost exactly like the 1Password CTF.

2. What Mega-Bounties Actually Buy

Start with the comparison set, because the 1Password program is easiest to read against its peers.

Apple, in October 2025, doubled its top award to $2,000,000 for zero-click remote-code-execution chains comparable to mercenary spyware, effective November 2025. Stack the bonuses — a Lockdown Mode bypass, a bug in beta software — and the ceiling climbs past $5,000,000. Since launching its public program in 2020, Apple says it has awarded over $35,000,000 to more than 800 security researchers.

Amazon ran an AI-focused research tournament where university teams received $250,000 upfront plus AWS credits, and winners earned up to an additional $700,000.

Pwn2Own listed a zero-click WhatsApp exploit as a single target worth up to $1,000,000 — the largest single target in the contest's history. No public winner was announced for it. Pwn2Own Berlin 2026 paid about $1,300,000 in total zero-day payouts.

Three programs, three purchases. A standing supply of a capability class. A funded research method. A timed demonstration against a named target. Apple is pricing the spyware-grade chain; Amazon is pricing AI-system talent it wants in the building; Pwn2Own is pricing a demonstrated zero-day against a specific platform on a specific day.

They differ in detail. They agree on a principle: a mega-bounty is the market's confession of what it considers scarcest. The price is the fear, made legible.

3. The 1Password Inversion: A Flag, Not a Class

Now the outlier.

1Password — AgileBits — runs a Capture the Flag bounty with a top reward of USD $1,000,000. The program is not new. 1Password has paid researchers through Bugcrowd since 2015, and the million is the third step in a deliberate ladder: $25,000, then $100,000 in March 2017, then $1,000,000 announced March 10, 2022. It began on Bugcrowd and later moved to HackerOne. For years the program provided a shared white-box test account; in a 2026 restructuring 1Password retired the shared account and the invite-on-request process entirely — the overhead of maintaining them had grown too large. You no longer need an invite to take part. The target vault and item IDs are now public, so you attempt the challenge from outside the account with your own tooling. The cryptographic boundary is identical whether you work from inside the account or outside it — which was always the case; only the mechanics of reaching the flag changed.

What you must capture is not a category. It is a thing. The flag is a secure note that contains "bad poetry," and to earn the reward you retrieve that note — today by working from outside the account against the now-public vault and item IDs. Only valid submissions that detail the steps used to capture it are eligible. The specification has always been this narrow — narrower, once. When the prize first jumped to $100,000 in 2017, the target was not just "bad poetry" but a "horrible haiku" stored in a vault you were never meant to open.

Sit with how different that is. Apple does not ask you to read one specific email out of one specific iPhone; it asks you to demonstrate a class of capability and then grades the severity. Pwn2Own gives you a named platform and a clock, but it is still buying the existence of an exploit against a target, judged by a panel. None of them is a single, fully specified end state.

1Password collapses the whole apparatus into one outcome. There is no severity tier. There is no partial credit. There is the note, or there is nothing. The contract has exactly one acceptance test, and the company that wrote it also built the system the test runs against.

Four columns comparing what mega-bounties buy: Apple a graded class of capability, Amazon a funded method and talent, Pwn2Own a demonstrated target on a clock — each drawn as a broad open shape — versus 1Password, drawn as a single exact red point labeled one artifact, the note or nothing.
Three programs buy a category and grade it. 1Password buys one fully specified outcome — the note, or nothing.

And it told you, in plain language, what it thinks of your chances:

"There are no known vulnerabilities that will award you access to the bad poetry; there is no starting point, and it's not a game with a guaranteed reward."

No known vulnerability. No starting point. No guaranteed reward. The dollar figure gets the headline. That sentence sets the terms of trade.

4. Logic-Proven Is Worth Zero Here

This is where the CTF stops being a curiosity and becomes a case study in my own thesis.

In The Machine That Reads Code I drew a line between two states a finding can be in. Logic-proven: the reasoning closes, the argument sounds correct, the chain hangs together when you narrate it. Execution-proven: there is an artifact — a PoC that runs in a reproducible environment and does the thing. Models produce the first reliably. The second still requires human-driven iteration.

The market is now flooded with the first kind. Hypotheses are cheap. A coding agent will hand you a confident paragraph about how some boundary could be crossed, for the price of a subscription. The hard, scarce, expensive work is dragging that paragraph across the gap into an artifact that actually executes.

The 1Password CTF is the only bounty I can point to that refuses, by construction, to pay one cent for the first kind.

You cannot submit a theory. You cannot submit a clever read of the architecture. You cannot submit a chain that "should" work. The only valid submission is the steps that produced the note — which means you had to already hold the note. Logic-proven is worth exactly $0 here. Only execution-proven clears, and what it clears is a million dollars.

1Password says as much in its own guidance for AI-assisted submissions. It tells researchers to treat a model's output as a hypothesis to verify rather than a conclusion, and to include a recording of the exploit running end to end before they submit anything. Read that against the thesis and it is the same line, drawn this time by the party holding the checkbook: the hypothesis is not the deliverable, the running artifact is. When the buyer writes execution-proof into the intake itself, the bottleneck has stopped being one researcher's private discipline and become a term of the market.

That is the verification bottleneck rendered as a legal instrument. The market produces vulnerability hypotheses faster than ever. 1Password's design simply declines to recognize hypotheses as a deliverable. The artifact is the entire deliverable. The flag is the proof, and the proof is the flag; there is no daylight between them. A million dollars is what the crossing costs, not the finding.

5. The Record as a Single Bit

Now the empirical anchor, and it is brutal.

1Password raised the top prize to $100,000 in March 2017. That reward stood for five years, until the million replaced it in 2022, and across those five years no one claimed the flag despite nearly 800 attempts. By the March 2022 announcement, 1Password had paid out about $103,000 to Bugcrowd researchers — averaging $900 per reward — and every detected bug was minor and never threatened sensitive customer data.

Look at what those numbers say next to the structure.

Every one of those attempts pointed at the same note. Through three prize increases since 2017, the flag count stayed at zero; the rewards that did land averaged $900 apiece. The headline prize converted the entire global effort into a single bit — solved or not solved — and the bit stayed 0. The $103,000 was paid for everything that was not the flag. The flag itself paid nothing, because no one produced it.

A binary oracle machine with roughly 800 thin attempt-lines feeding in from the left and a single red numeral 0 as its only output, beside a ledger showing $103,000 paid for everything that is not the flag and $0 captured for the flag itself, over a price ladder rising $25K to $100K to $1M.
The instrument is a one-bit oracle. Ten times the prize, three increases, ~800 attempts — the output has stayed 0.

This is the part outsiders miss when they call it a million-dollar bug bounty. It is not a bounty in the ordinary sense, where many researchers chip away at a surface and many of them get paid. Those small payouts are the byproduct — the minor bugs that turned up while people hunted the needle. The actual instrument is closer to a binary oracle with a seven-figure output and, historically, an output of 0. The minor bugs are noise around an untouched signal.

The reward went up tenfold. The structure did not change. A bigger number on a single-bit oracle does not improve your odds of flipping the bit; it raises the price the company is willing to pay precisely because it believes the bit is extraordinarily hard to flip. Apple prices its fear of spyware chains. 1Password prices its confidence in its own architecture.

And you can watch that confidence in the open. 1Password publishes its security patch history, and the revealing thing is what is not on it. The fixes sit at the periphery — a deauthorized device's secret key cleared from local storage, a deprecated provisioning bridge blocked from authenticating, sensitive operations rehardened to verify a subkey instead of the Account Unlock Key. Careful work, some of it credited by name to the researcher who reported it, and none of it the encryption; even the entries closest to the core only harden the key-handling around the vault, never break into it. The company can afford to show every patch it ships precisely because none of them has ever been the flag. That is what "we trust the math" looks like as an operating fact rather than a slogan: the bugs live in the plumbing; the cryptography at the center has stayed untouched.

6. The Design Philosophy Is the Adversary

There is one more public fact that explains why the bit stays at 0, and it is not a secret. It is a published document.

1Password maintains a Security Design White Paper describing an end-to-end encryption architecture: account keys derived client-side, a server designed never to see the unencrypted master key or vault contents. I cite that only at the level of stated design intent, because that is the only level any outsider should claim. But the stance reshapes the economics of the flag.

On most targets, the adversary is a defect — the gap between what the engineers meant and what they shipped. You hunt for the place where intention and implementation diverged. The 1Password CTF inverts even that. The thing standing between a researcher and the note is not, on paper, a bug. It is the intended design working as designed.

So to claim the million, you are not looking for a place where someone was careless. You are testing whether the design philosophy itself holds under adversarial pressure. A graded severity scale assumes a system leaks in degrees. This architecture's stated purpose is that it does not leak at all. The only honest test of that claim is binary: produce the note, or you have not falsified the design. That is why the reward is one execution-proven outcome rather than a ladder of findings.

And it is a far lonelier thing to attack than a misconfigured endpoint. The adversary is the architecture's stated goal. It does not get tired. It does not make exceptions for a good argument.

Two panels: on the usual target an arrow slips through a crack in the wall, labeled a defect where intent and build diverged; on the 1Password CTF an arrow strikes an unbroken latticed wall and stops, its tip fraying into red dashes, labeled the wall is the intended design.
On most targets the adversary is a defect. Here it is the architecture working exactly as intended.

The rules are explicit that the company won't provide direct assistance to capture the flag, so the only thing worth examining from the outside is the stance the structure forces on any researcher. So let me stay there.

A target defined as "no starting point" reorganizes how you reason about risk and time. There is no severity ladder to climb, so the expected value of any path that is not the path is zero — which clarifies the mind and also empties it. And the years-long record is not trivia; it is a prior. Every hour you spend is an hour that nearly eight hundred others already spent without flipping the bit. You are not racing a clock. You are arguing with a track record.

7. A Reachability Verdict, Argued From the Outside

Is the flag reachable? An honest answer, built only from public material, has to hold two truths at once.

The first: nothing the company has published guarantees the flag is unreachable. The whole premise of a bug bounty is that the designers' confidence is a hypothesis, not a theorem. 1Password states a design intent — client-side key derivation, a server engineered never to see plaintext. Intent is not a proof of correctness. "No known way in" is not "no way in." The existence of the program is itself an acknowledgment that some gap could exist that the company has not found — because implementation security is the one claim you cannot prove by asserting it. The million is not an admission of doubt. It is the opposite: a company confident enough in its design to put the largest possible price on being wrong, and to turn any flaw that does exist from something an attacker would hoard into something a researcher will disclose.

The second, and the one I weight more heavily as an outside analyst: every public signal points the same direction. Uncaptured since 2017, through three prize increases to $1,000,000. Nearly 800 attempts producing only minor bugs. A flat, deliberate framing — no known vulnerability, no starting point, no guaranteed reward — that reads less like a challenge and more like an honest disclosure of base rates. A structure that pays nothing for the abundant half of modern research and everything for the scarce half, against an architecture explicitly built to make the scarce half scarcer still.

So my verdict is a probability, not a certainty, and I want to be exact about which. Reachable in principle: yes, by the definition of a bounty. Reachable in practice, judged from the public record alone: I would bet against any given attempt. The structure was engineered to make execution-proven success a rare event, and the historical frequency of that event is, so far, zero.

That is not pessimism. It is the same discipline the thesis demands everywhere else. Treat the optimistic read as a hypothesis. Withhold belief until an artifact runs. The CTF simply makes that discipline non-negotiable, because here the artifact is the only thing the contract will recognize.

8. The Question I Can't Close: Will the Next Model Find It?

There is one reflection I keep circling, and honesty requires that I leave it open rather than pretend to resolve it.

Today's models broke the finding problem. They read a codebase faster than any human, never tire, and surface hypotheses for the price of credits. What they do not do — yet — is close the distance to the artifact. Twenty-two candidates, two working exploits, roughly 350 attempts. The 1Password flag sits on the far side of exactly that distance. It is not a finding problem. It is an execution problem, and execution is the half the machines have not learned to do cheaply.

So here is the question I cannot close. Does that gap survive the next generation?

Not this model — the next one, or the one after. Pick your placeholder for the leap: a future Claude, a GPT-whatever, a frontier model two generations out, whatever the labs ship when the curve bends again. Imagine reasoning that does not merely narrate a plausible chain but drives it, end to end, into something that runs. Imagine the cost of execution-proving collapsing the way the cost of finding already has.

If that happens, the verdict in the previous section gets rewritten — not because the architecture got weaker, but because the cheap half of research finally annexed the expensive half. The single bit would flip not when someone gets clever, but when proving itself stopped being scarce.

I do not think we are there, and I will say why, because the reasons are the argument. The gap between logic-proven and execution-proven is not obviously a reading problem. A larger context window and a sharper reasoner make better hypotheses — and better hypotheses are still hypotheses. And this particular target was built, on purpose, so that the only acceptance test is the artifact itself. A system designed to make logic-proven worthless is close to the worst possible place to spend a capability that produces mostly logic.

But I hold that loosely. The whole thesis of The Machine That Reads Code was that a curve bent and a bottleneck moved. Curves bend again. If some later model ever makes execution as cheap as reading, the most honest thing I can say is that I do not know which side of the bit it would land on — and that the people who wrote the contract probably do not know either. That uncertainty is the reason the million is still on the table.

9. The Machine Reads the Code

Put the whole picture together and the 1Password CTF stops looking like an outlier and starts looking like a forecast.

The mega-bounty market is converging on a single shape. As discovery collapses toward free — as models surface candidate after candidate for the price of credits — the only thing left worth a serious price is the proof. The others still pay, partly, for finding: for the category, the talent, the demonstrated existence. 1Password has already walked to the end of that road. It pays for nothing but the artifact. The note in your hand, with the steps that put it there, or zero.

That is the verification bottleneck written into a contract, years before most programs will admit they are heading the same way. A market drowning in cheap hypotheses will, eventually, stop paying for hypotheses. It will pay for the thing that runs. The reading is cheap now, and getting cheaper. The note in your hand is the only thing that has ever counted, and since 2017 the count has stayed zero. A million dollars is the market's honest estimate of how far apart those two facts still are.

I closed the earlier piece with a line I still believe. The machine reads the code. It still falls to you to say what it means.

The 1Password CTF adds the harsher corollary. Saying what it means is no longer enough. You have to hold the note.

Sources

keep reading

More Research

All articles →