← Back to live feed · 1 stories across 1 day

Sunday, Sep 20, 2026

1 story
1
Researchers Use Claude to Reach OpenAI’s Private Code in Under 72 Hours
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords OpenAI

Three researchers at security startup Hacktron AI exploited an image decoder bug and a login flaw to take over OpenAI employee ChatGPT and Codex accounts and reach the company’s private GitHub code repository. Working under OpenAI’s bug bounty program, they used Anthropic’s Claude Opus 5 to carry out the July 25 breach in less than 72 hours, spending under $3,000 on AI tokens.

The researchers demonstrated access by having an employee’s Codex account submit a harmless proposed code change to the repository. OpenAI paid them a $6,500 bounty and fixed the single sign-on flaw roughly 14 hours after their report. The company said its review found only “limited reads” of private repository metadata and code changes, and no model weights were believed exposed.

The breach was part of Hacktron’s broader HEIF Heist investigation into libheif, an image decoding library used by OpenAI’s Discourse community forum. The exploited bug had already been fixed upstream, but the fix was not flagged as security relevant and the vulnerable version remained in Discourse. Hacktron identified attack paths affecting Slack, Meta, GitHub Enterprise, Rails, Next.js and ImageMagick, with vulnerabilities that could expose information or let attackers run code remotely.

Image via @intcyberdigest on X
Earlier version from Saturday, Sep 19
Researchers Use Anthropic’s Claude to Breach OpenAI’s Private Code Repository
103 tweets • 75 sources
See all 105 tweets →