← Back to live feed · 1 stories across 1 day
Friday, Sep 18, 2026
1 story1 Three Researchers Breach OpenAI Monorepo Using Claude Opus 5 AI Sep 17, 7:17 PM EDT 34/26
Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens. While Claude Opus 4.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens.
OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub.