Skip to main content

Researchers used Claude to hack OpenAI in under 72 hours

A three-person team from Hacktron used Anthropic's Claude to breach OpenAI employee accounts via a HEIF image vulnerability in under 72 hours.

AI-written
Inewgen
19 Sep 2026Source: The Verge2 min read (0 views)
Share
Researchers used Claude to hack OpenAI in under 72 hours

Stock photo for illustration only, not from the actual event

Font size
  • A three-person research team breached OpenAI in under 72 hours using Claude Opus 4.8 and 5
  • The hack exploited HEIF image processing flaws on the Discourse forum service
  • Researchers gained access to OpenAI's GitHub repository known as Monorepo
  • The HEIF Heist project cost under $3,000 in tokens and took 1-2 days to adapt

A team of three independent security researchers from Hacktron managed to compromise OpenAI employee accounts with the assistance of Anthropic’s Claude Opus 4.8 and 5 models, accomplishing the feat in less than 72 hours, according to reports from The Wall Street Journal.

The breach was executed through Discourse, the third-party platform hosting OpenAI's community forums, by exploiting vulnerabilities in how the system processes HEIF image files. According to Hacktron, Claude Opus 5 launched on the evening of July 24th, and by 10 AM the following day, the team leveraged it to achieve remote code execution on Discourse Cloud and access OpenAI's instance.

artificial intelligence ai chat screen code matrix

Stock photo for illustration only, not from the actual event

72Hours to breach system
$3,000Max token budget used
$6,500Bug bounty paid by OpenAI

During the incident, the researchers gained access to OpenAI's GitHub repository named "Monorepo," which reportedly holds the company's algorithmic secrets. While they stopped short of downloading the internal code directly, they submitted a pull request from an employee's Codex account to prove their access.

"I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions."

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

Mohan Pedhapati, Hacktron CTO

Dubbed the HEIF Heist project, the exploit took only one or two days to adapt for targeting other major entities including Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick. The operation utilized less than $3,000 in AI tokens, and to the researchers' knowledge, only one target, Shopify, successfully detected the activity.

This incident highlights a significant shift in cybersecurity dynamics, where generative AI tools significantly lower the barrier and time required to discover complex vulnerabilities, enabling small teams to challenge the defenses of major tech giants.

The reported vulnerabilities have since been patched by Discourse and OpenAI. Hacktron confirmed that OpenAI paid them $6,500 for identifying and disclosing the bug.

Source: The Verge

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article