
Cyber Security
Researchers Used Claude To Hack Into OpenAI’s Internal Repositories
Updated on Fri, Sep 18, 2026
Security researchers at Hacktron AI used Anthropic’s Claude to help exploit vulnerabilities that eventually gave them access to OpenAI employee ChatGPT and Codex accounts and a path into the company’s private software repositories.
The three-person team completed the attack chain in less than 72 hours, responsibly disclosed the flaws, and received a $6,500 reward from OpenAI. However, the researchers said they deliberately avoided accessing sensitive internal code and stopped after creating a harmless proof-of-concept pull request.
TL;DR
- Hacktron AI chained an image-processing vulnerability with an OpenAI sign-in flaw to compromise employee accounts.
- Claude Opus 4.8 initially struggled to create a reliable exploit, while Claude Opus 5 succeeded within hours.
- The researchers reached OpenAI’s internal GitHub environment but said they avoided accessing sensitive code.
- OpenAI and Discourse have since fixed the issues, while OpenAI paid Hacktron a $6,500 bounty.
Claude Helped Turn An Image Bug Into A Working Exploit
According to Hacktron AI’s first-party disclosure, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini began examining the image-upload pipeline used by OpenAI’s community forum, community.openai.com, in July.
The forum runs on Discourse. Hacktron discovered that HEIC and HEIF image uploads could eventually be passed through the open-source libheif image-decoding library, where the researchers identified a heap buffer overflow that could potentially be turned into remote code execution.
Hacktron initially gave the problem to Anthropic’s Claude Opus 4.8. The researchers said the model could develop an exploit when address-space layout randomization was disabled but struggled to produce a dependable attack against Discourse’s normal configuration.
That changed after Anthropic released Claude Opus 5 on July 24.
“Within hours of Opus 5’s release, we gave it the same problem and it succeeded,” Hacktron said in its disclosure.
The team said Opus 5 first produced a working ARM64 exploit for a local Mac within around three hours before adapting it to the x86-64 environment used by Discourse. By the morning of July 25, the researchers had achieved remote code execution through an image upload.
TechCrunch similarly reported that Claude Opus 4.8 struggled to develop a working exploit before the newer Opus 5 managed to crack the problem. Forbes also highlighted the sharp capability difference between the two model generations.
A Second Flaw Opened OpenAI Employee Accounts
Compromising the community forum was only the first stage.
Hacktron said it also discovered a flaw in OpenAI’s single sign-on infrastructure. Session credentials associated with the forum could provide access to ChatGPT and Codex accounts, including accounts belonging to OpenAI employees.
Quartz reported that the problem involved session tokens issued through the forum remaining valid across other OpenAI products. This meant the Discourse vulnerability could become an entry point into a much broader OpenAI environment.
Hacktron emphasized that this second problem was an OpenAI identity issue rather than a vulnerability specific to Discourse.
After gaining access to an employee account, the team discovered that the employee’s Codex account was connected to OpenAI’s GitHub organization.
“The scope of what we could theoretically access was huge,” Hacktron said, referring to connected services that could include GitHub, Slack, and email.
Researchers Reached OpenAI’s Internal Repository
To prove the impact without examining confidential information, Hacktron instructed the compromised employee’s Codex account to create a harmless pull request in OpenAI’s internal monorepo.
The researchers said they did not inspect or download OpenAI’s proprietary source code and stopped further testing after demonstrating the access.
The Guardian also reported that Hacktron had access to the repository but deliberately refrained from downloading its contents. Quartz cited OpenAI as saying its review found limited reads of private-repository metadata and code changes.
The Wall Street Journal, which first reported the development, said the researchers had reached OpenAI’s internal systems after compromising employee authentication credentials.
This distinction matters. The researchers proved that the vulnerabilities created a path into sensitive internal resources, but the publicly disclosed evidence does not show that they stole OpenAI source code or other confidential data.
Hacktron Reported The Vulnerabilities Within Hours
Hacktron says it first achieved remote code execution and administrative access to OpenAI’s Discourse environment on July 25.
The researchers submitted the OpenAI-related issue through Bugcrowd that morning, demonstrated employee account access and the harmless pull request later that day, and stopped testing at approximately 15:30 UTC.
OpenAI confirmed its fix roughly 14 hours after Hacktron’s initial submission. Discourse subsequently prepared its own fix by July 27 and published an advisory the following day.
OpenAI told news outlets, “We thank the researchers for contacting us and sharing their findings.”
The company said it narrowed permissions attached to Community sign-in tokens and revoked affected tokens and sessions.
There is one important caveat surrounding the $6,500 bounty. Hacktron’s disclosure says OpenAI clarified that testing against the Discourse-hosted community.openai.com was explicitly outside its bug bounty program. The payment covered the OpenAI-side security finding rather than the researchers’ actions against Discourse.
AI Is Cutting The Cost And Time Needed To Exploit Vulnerabilities
For Hacktron, the bigger takeaway was how dramatically AI reduced the work required to transform software vulnerabilities into functional exploits.
The OpenAI attack chain took less than 72 hours from initial discovery to internal repository access. Hacktron said the wider HEIF Heist research project, which examined the same family of image-processing weaknesses across companies and software including Slack and Meta, involved three researchers, lasted around two months, and cost less than $3,000 in AI-model tokens.
Topics for more insights:
However, Hacktron stressed that the research was not completely autonomous and continued to require skilled human guidance.
“Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said.
Forbes reported the same figures, noting that the researchers described the OpenAI portion as taking only a few days of agent work and several hours of human effort.
TechCrunch also quoted Gray Swan CEO Matt Fredrikson saying commercially accessible AI tools were lowering the barrier to sophisticated cybersecurity work, raising concerns about what the same capabilities could mean in malicious hands.
OpenAI Redirected Engineers Toward Security
The incident arrived during a broader period of security scrutiny for OpenAI.
In a separate July incident, OpenAI disclosed that experimental AI agents escaped restrictions during a cybersecurity evaluation and accessed systems belonging to Hugging Face. OpenAI later said it strengthened controls following that incident.
Quartz, citing The Wall Street Journal, reported that OpenAI President Greg Brockman said the company redirected 25% of its production engineers toward security work following the incidents and uncovered additional issues that were subsequently fixed.
The Hacktron research also demonstrates an unusual dynamic in the competition between frontier AI companies: researchers used an Anthropic model to help identify a path into OpenAI’s infrastructure.
More importantly for cybersecurity teams, however, the episode shows how rapidly AI-assisted vulnerability research is advancing. Claude did not independently decide to hack OpenAI, and Hacktron’s researchers remained actively involved, but the researchers say newer models substantially reduced the expertise and time required to turn a difficult memory-corruption flaw into a working attack.
First published on Fri, Sep 18, 2026
Liked what you read? That’s only the tip of the tech iceberg!
Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!
Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.
Dive into TechDogs' treasure trove today and Know Your World of technology like never before!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...


