← Back to live feed · 1 stories across 1 day
Friday, Sep 18, 2026
1 story1 Researchers Use Claude Opus 5 to Breach OpenAI Internal Code in 72 Hours AI Sep 17, 11:20 PM EDT 63/52
Three security researchers from Hacktron AI exploited a vulnerability in an image-processing library to enter OpenAI's internal GitHub monorepo on July 25. The team used Anthropic's Claude Opus 5 model to chain a flaw in the Discourse forum host into the theft of authentication tokens for employee ChatGPT and Codex accounts. This access allowed the team to read internal software and submit a proof-of-concept pull request before reporting the breach through the company's bug bounty program.
OpenAI paid the researchers a $6,500 reward and patched the single sign-on flaw roughly 14 hours after the disclosure. The internal review found only limited reads of private repository metadata and code changes, with no model weights exposed. The attackers noted that while Claude Opus 4.8 struggled to make the exploit reliable, Opus 5 produced a working version within three hours of its release.