← Back to live feed · 1 stories across 1 day

Friday, Sep 18, 2026

1 story
1
Three Researchers Breach OpenAI Monorepo Using Claude Opus 5
topics 🔒 Cybersecurity🤖 AI💻 Tech tags AIAI RegulationAI LegalTechCybersecurity keywords Hacktron AIAnthropicOpenAI

Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens. While Claude Opus 4.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens.

OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub.

Image via @andrewcurran_ on X
You're reading an older version of the story.
Earlier version from Thursday, Sep 17
OpenAI Pays $6,500 Bounty For Hacktron Claude Breach Of Software Cache
2 tweets • 2 sources
See all 34 tweets →