← Back to live feed · 1 stories across 1 day

Friday, Sep 18, 2026

1 story
1
Researchers Use Claude Opus 5 to Breach OpenAI Internal Code in 72 Hours
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords Hacktron AIOpenOpenAI

Three security researchers from Hacktron AI exploited a vulnerability in an image-processing library to enter OpenAI's internal GitHub monorepo on July 25. The team used Anthropic's Claude Opus 5 model to chain a flaw in the Discourse forum host into the theft of authentication tokens for employee ChatGPT and Codex accounts. This access allowed the team to read internal software and submit a proof-of-concept pull request before reporting the breach through the company's bug bounty program.

OpenAI paid the researchers a $6,500 reward and patched the single sign-on flaw roughly 14 hours after the disclosure. The internal review found only limited reads of private repository metadata and code changes, with no model weights exposed. The attackers noted that while Claude Opus 4.8 struggled to make the exploit reliable, Opus 5 produced a working version within three hours of its release.

Image via @andrewcurran_ on X
Earlier version from Thursday, Sep 17
Hacktron AI Breaches OpenAI Private Code Using Claude Opus 5 in 72 Hours
46 tweets • 37 sources
See all 63 tweets →