> Absurdly bad in terms of reward

This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides.

> This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.

The reason they were looking for bugs was in the context of a B2B relationship, not as a someone independent on their nights and weekends.

If they give them any additional compensation it would probably be in some amount of free or discounted services, which is what they’d want anyway.

The main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.

Literally paid in exposure.