← Back to live feed · 1 stories across 1 day
Friday, Sep 18, 2026
1 story1 Hacktron AI Breaches OpenAI Private Code Using Claude Opus 5 in 72 Hours AI Sep 17, 9:45 PM EDT 46/37
A team of independent bug hunters utilized a vulnerability in a third party image library to infiltrate internal software repositories and hijack staff accounts. The researchers from Hacktron AI exploited a heap buffer overflow in libheif, a tool used by OpenAI's forum host Discourse, to steal authentication tokens. These credentials granted entry to employee ChatGPT and Codex accounts, enabling a breach of the company's private GitHub monorepo in less than 72 hours using Anthropic's Claude Opus 5.
OpenAI paid a $6,500 bug bounty for the disclosure and stated that no model weights were exposed, although its review found limited reads of repository metadata. The operation cost less than $3,000 in AI tokens. The team observed a performance jump between model versions, noting that while Claude Opus 4.8 struggled to make the exploit reliable, the new Opus 5 produced a working version within 3 hours of its launch.