← Back to live feed · 1 stories across 1 day

Friday, Sep 18, 2026

1 story
1
Hacktron AI Uses Claude Opus 5 to Breach OpenAI Internal Code for $6,500 Bounty
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords Greg Brockman

Three security researchers accessed an internal GitHub repository and employee ChatGPT profiles by exploiting a flaw in an image parsing library on July 25. The Hacktron AI team used a HEIF image upload to trigger a heap buffer overflow in the libheif library used by a Discourse community forum, granting remote code execution. A second vulnerability in OpenAI's single sign-on process then allowed the researchers to seize Codex and ChatGPT accounts linked to corporate Slack, Outlook, and GitHub access.

Anthropic's Claude Opus 5 produced a working exploit within three hours of its release after the previous Opus 4.8 version failed to do so. OpenAI paid a $6,500 bug bounty for the discovery, which also uncovered vulnerabilities in Meta and Slack as part of a broader investigation called HEIF Heist. In response to this breach and another at Hugging Face, Greg Brockman reassigned 25% of the company's production engineers to security tasks.

Image via @nrehiew_ on X
Earlier version from Friday, Sep 18
Researchers Breach OpenAI Internal Code Using Anthropic Opus 5 Model
87 tweets • 63 sources
See all 89 tweets →