Researchers used Claude to hack OpenAI in under 72 hours
A three-person team from Hacktron used Anthropic's Claude to breach OpenAI employee accounts via a HEIF image vulnerability in under 72 hours.

Stock photo for illustration only, not from the actual event
- A three-person research team breached OpenAI in under 72 hours using Claude Opus 4.8 and 5
- The hack exploited HEIF image processing flaws on the Discourse forum service
- Researchers gained access to OpenAI's GitHub repository known as Monorepo
- The HEIF Heist project cost under $3,000 in tokens and took 1-2 days to adapt
A team of three independent security researchers from Hacktron managed to compromise OpenAI employee accounts with the assistance of Anthropic’s Claude Opus 4.8 and 5 models, accomplishing the feat in less than 72 hours, according to reports from The Wall Street Journal.
The breach was executed through Discourse, the third-party platform hosting OpenAI's community forums, by exploiting vulnerabilities in how the system processes HEIF image files. According to Hacktron, Claude Opus 5 launched on the evening of July 24th, and by 10 AM the following day, the team leveraged it to achieve remote code execution on Discourse Cloud and access OpenAI's instance.

Stock photo for illustration only, not from the actual event
During the incident, the researchers gained access to OpenAI's GitHub repository named "Monorepo," which reportedly holds the company's algorithmic secrets. While they stopped short of downloading the internal code directly, they submitted a pull request from an employee's Codex account to prove their access.
"I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions."
Dubbed the HEIF Heist project, the exploit took only one or two days to adapt for targeting other major entities including Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick. The operation utilized less than $3,000 in AI tokens, and to the researchers' knowledge, only one target, Shopify, successfully detected the activity.
This incident highlights a significant shift in cybersecurity dynamics, where generative AI tools significantly lower the barrier and time required to discover complex vulnerabilities, enabling small teams to challenge the defenses of major tech giants.
The reported vulnerabilities have since been patched by Discourse and OpenAI. Hacktron confirmed that OpenAI paid them $6,500 for identifying and disclosing the bug.
Source: The Verge
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment