← Back to live feed · 1 stories across 1 day

Friday, Sep 18, 2026

1 story
1
Researchers Use Claude to Breach OpenAI’s Private Code Repository
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords Hacktron AIHacktronDiscourseOpen

Three researchers at security startup Hacktron AI used Anthropic’s Claude to exploit two vulnerabilities on July 25, taking over OpenAI employee accounts and reaching its private GitHub code repository in less than 72 hours. The work, conducted under OpenAI’s bug bounty program, cost less than $3,000 in AI tokens. Hacktron said Opus 4.8 struggled to produce a working exploit, but Opus 5 succeeded within hours of its release.

A crafted HEIF image uploaded to OpenAI’s public community forum exploited a flaw in the libheif image decoder, allowing the researchers to run commands on the forum server. A separate flaw in OpenAI’s single sign-on system then let them take over ChatGPT and Codex accounts belonging to employees and some unaffiliated users, reaching connected services including Slack, Outlook and GitHub. They demonstrated access by directing an employee’s Codex account to open a harmless proposed code change in OpenAI’s internal repository. The proposal was not accepted, and the researchers said they stopped without downloading source code.

OpenAI fixed the sign-on flaw roughly 14 hours after the report and paid the researchers $6,500. Discourse, the forum software provider, received a separate report on Saturday and had a fix on Monday. OpenAI said its review found only “limited reads” of private repository metadata and code changes, and that no model weights were believed to have been exposed.

Image via @s1r1u5_ on X
Earlier version from Friday, Sep 18
Hacktron AI Uses Claude Opus 5 to Breach OpenAI Internal Code for $6,500 Bounty
89 tweets • 65 sources
See all 95 tweets →