← Back to live feed · 1 stories across 1 day

Friday, Sep 18, 2026

1 story
1
Hacktron AI Breaches OpenAI Private Code Using Claude Opus 5 in 72 Hours
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords OpenAI

A team of independent bug hunters utilized a vulnerability in a third party image library to infiltrate internal software repositories and hijack staff accounts. The researchers from Hacktron AI exploited a heap buffer overflow in libheif, a tool used by OpenAI's forum host Discourse, to steal authentication tokens. These credentials granted entry to employee ChatGPT and Codex accounts, enabling a breach of the company's private GitHub monorepo in less than 72 hours using Anthropic's Claude Opus 5.

OpenAI paid a $6,500 bug bounty for the disclosure and stated that no model weights were exposed, although its review found limited reads of repository metadata. The operation cost less than $3,000 in AI tokens. The team observed a performance jump between model versions, noting that while Claude Opus 4.8 struggled to make the exploit reliable, the new Opus 5 produced a working version within 3 hours of its launch.

Image via @andrewcurran_ on X
You're reading an older version of the story.
Earlier version from Thursday, Sep 17
Three Researchers Breach OpenAI Monorepo Using Claude Opus 5
34 tweets • 26 sources
See all 46 tweets →