Miju Labs

The security dossier

Paying the crowd

Gray Swan buys perpetual worldwide rights to an attack trajectory for about $3.77; Mercor pays $70–95 an hour and up for the same skill. Tournament and payroll are different products, and the buyer of a dataset wants the expensive one.

medium confidence8 minupdated 2026-08-30compensation · tournament · consent · licensing · unit economics

Two price systems operate in this market, roughly two orders of magnitude apart, and the gap is not an inefficiency. It is a question about which risk the buyer is paying to transfer.

The tournament price

Gray Swan AI publishes unusually good numbers about its own crowd, and they are startling (Arena About):

  • 13,000+ community members (Forbes and the Series A release both say 15,000; likely registered-versus-active or date drift)
  • $490,000+ distributed in rewards — total, lifetime
  • 4 million+ attack attempts submitted
  • 130,000+ successful breaks
  • 100+ participants placed into paid red-teaming roles

The derived ratios are arithmetic, not estimates:

UnitRate
Per community member, lifetime~$33
Per successful break~$3.77
Per attack attempt~$0.12

These are the economics of a game, not a labour market. The design makes that deliberate. The Indirect Prompt Injection Q1 2026 challenge carried a $40,000 pool split $14,500 for "Most Breaks Per Wave" across the top 20, $14,000 for "Most Breaks Overall" across the top 40 with $2,000 for first, and $11,500 in per-model pools shared among the first 500 breaks — with a $100 minimum payout threshold below which earnings carry forward indefinitely (rules). A $40K pool spread over roughly 60 leaderboard positions and capped per-model pools means the median participant in a given challenge earns literally zero. Pools across the Arena run $20,000 to $170,000+. Forbes follows one unusually successful participant, Kameron Bettridge, who earned $10,000 across 1,000+ challenges in about a year (Forbes) — a figure that annualises below minimum wage for any meaningful hour count.

The payroll price

Against $3.77 a break, here is what buyers pay when they want coverage and judgement rather than rare artefacts — Mercor's posted marketplace rates:

WorkPosted rateStatus
Offensive security and vulnerability research$200–250/hr[UNVERIFIED]
Harm labelling$100–150/hr[UNVERIFIED]
Scenario design$80–95/hr[UNVERIFIED]
Completed pentest task$1,750–2,150 per task[UNVERIFIED]
Cybersecurity experts, vulnerability analysis$70–90/hrlisting
Cyber security experts, defensive evaluation$85–95/hrlisting

Only the bottom two rows are verified against a live Mercor listing. The four rates above them are carried from the client brief and could not be traced to a primary posting in this research — they are directionally consistent with the verified rows and with the $120–200/hr senior AI-red-team contractor band [WEAK] (infosec.qa), but they should be re-checked against Mercor's board before anyone prices against them. Handshake AI is reported to pay up to $80/hr for comparable work, also [UNVERIFIED] and also carried from the brief rather than from a posting in this research. The frontier labs themselves run prize programmes on top: Anthropic's Model Safety Bug Bounty pays up to $35,000 per novel universal jailbreak on a sliding scale, run through HackerOne with NDAs for all participants (Anthropic); OpenAI's programmes pay $200–$20,000 standard and up to $100,000 for exceptional critical findings; Google's AI VRP tops out at $30,000 with bonuses and explicitly excludes prompt injection, jailbreaks and alignment issues [WEAK — aggregated] (Wraith).

Which structure a dataset buyer actually wants

The two price systems transfer different risk, and that determines which product each can produce.

Piece-rate and tournament pricing transfers discovery risk to the practitioner. The buyer pays only for outcomes; the crowd absorbs every unpaid hour. It works when the buyer wants rare artefacts — a universal jailbreak, a critical vulnerability — and does not care about coverage, reproducibility or schedule.

Hourly and payroll pricing transfers discovery risk to the buyer, who gets coverage, schedule certainty, reproducibility and provenance in exchange. That is what you need when the deliverable is a dataset rather than a finding.

The shape mismatch

An AI lab training a security-capable agent needs trajectories that are broad across vulnerability classes rather than clustered on high-payout targets, reproducible, documented in reasoning as well as outcome, consistently formatted, and legally clean. A bounty crowd optimises for none of those. Hunters rationally cluster on high-payout, low-effort targets, document only enough to claim the bounty, and never write down the forty hypotheses that failed — which is precisely the reasoning data most valuable for training.

Three pieces of evidence say that mismatch is real rather than theoretical.

Bugcrowd, sitting on 500,000+ researchers, built its RL environments from open-source CVEs instead. Its 21 May 2026 launch targets "large language model providers and frontier AI research teams building security-aware agents," built on technology from its Mayhem Security acquisition, and states flatly that "no customer data or security researchers are used at any stage of the training process" (Bugcrowd). A platform with the crowd chose to synthesise around it, because reproducible, rights-clean, uniformly-formatted environments were easier to manufacture than to extract.

HackerOne's agentic tooling draws from "public benchmarks, internal benchmarks, public CVEs, and opt-in sidecar runs" — note "opt-in sidecar runs," a payroll-shaped, consented collection mechanism bolted onto a piece-rate platform (Critical Thinking Ep. 162).

And the buyers themselves run both. Anthropic pays up to $35,000 for a novel universal jailbreak and contracts Irregular for embedded evaluation work. That split is the answer: hourly contracts for baseline coverage and reasoning capture, with a bonus or tournament layer for rare high-value discoveries. Copying only the cheap half produces a corpus nobody can train on.

The fact that decides the recruiting story

Gray Swan's Arena rules state that by submitting, participants grant "Gray Swan AI and its partners an irrevocable, worldwide license to use and share the submission for any purpose" (Arena About).

Perpetual, sublicensable, unrestricted rights to every attack trajectory, at an average of ~$3.77 per successful break. That is the single most important commercial fact in the supply picture, and it is published on the company's own page.

The other half of the story is what happened when a platform's users noticed. HackerOne's terms contained the line "HackerOne may use confidential information to develop or improve its services, for example, to identify trends and to train AI models." The researcher community reacted badly in January and February 2026. CTO Alex Rice responded that HackerOne is not training LLMs on researcher submissions — that the "train AI models" language predates modern LLMs and referred to a spam classification engine using regression analysis — and pointed to Section 8 of the community terms, under which researchers retain IP, HackerOne holds a limited service-provision licence, customers get slightly broader rights to secure their own systems, and neither permits resale or redistribution. HackerOne committed to updating the terms to distinguish legacy ML from LLM training (Critical Thinking Ep. 162).

Resolved by denial

The controversy was settled by denying that the data was being used, not by building a mechanism for consented, compensated use. The largest corpus of human attack trajectories in existence is contractually locked, and its owner has publicly promised not to monetise it this way.

So: the platform with the best data will not sell it, and the platform that does sell to labs chose to synthesise around its own researchers. Nobody has built explicit paid, consented, per-artefact provenance. That is a recruiting asset no incumbent offers, aimed at a population that has already organised around exactly this grievance — see Offensive supply on why the Critical Thinking podcast is the highest-leverage channel.

The corollary is a constraint, not just an opportunity. Practitioners must be paid enough that a full, perpetual, sublicensable assignment is uncontroversial, because a dataset with murky provenance is unsellable to a frontier lab, and because this community demonstrably notices and objects. Rights cleanliness is the product feature; the rate is what buys it.

The employer-IP problem, and the market's answer to it

The obvious objection to recruiting working security professionals is that their employers may claim what they produce. The market has already written a clause for it: Mercor's own contributor terms warrant that the work "will not involve access to confidential or proprietary information from any employer, client, or institution."

That is not a legal opinion, and it does not resolve every jurisdiction or every employment agreement. But it is the standard the largest expert-data marketplace has adopted, and it defines the shape of the answer: artefacts authored from scratch for the buyer, never extracted from a day job. For defensive work in particular — where the temptation to bring real alert data is strongest — this constraint is doing most of the work of keeping the corpus saleable. See Defensive supply.

What this implies about margin

At $70–95/hr for the verified volume tier, and something above it for senior offensive work, fully-variable contributor cost is roughly knowable. What is not knowable is the sale price: no public figure exists for what a lab pays per hour or per delivered trajectory of red-team data anywhere. Gross margin on this business therefore cannot be modelled from public information, and any deck that models it is inventing the numerator. See What a rake can actually be and GMV is not revenue for why that distinction is enforced everywhere in this atlas, Expert data for frontier labs for the market this slice sits inside, and Sizing the cyber pot for what can be bounded instead.

The missing numerator

The single most valuable fact obtainable through primary conversation: the rate a frontier lab pays per hour, per trajectory, or per delivered environment for expert cyber data. Also unestablished: bug bounty platform take rates (no platform publishes a commission), Gray Swan's revenue mix between software licences and paid lab evaluations, and researcher compensation inside HackerOne's own AI Red Teaming product.