TL;DR
Ethical hackers at Hacktron AI used Anthropic's Claude Opus 5 to breach OpenAI's internal codebase in under 72 hours, exposing a chained exploit that reached private GitHub repositories and employee accounts.
What happened
- Hacktron AI, a US-based cybersecurity startup, breached OpenAI on July 25, 2026, disclosing publicly on September 18.
- The attack chain: malicious HEIF image upload triggered a libheif heap overflow on OpenAI's Discourse forum, enabling Remote Code Execution, then an SSO misconfiguration let researchers impersonate a privileged OpenAI employee.
- Claude Opus 5 analyzed raw server memory data and generated the precise weaponized HEIF exploit code; earlier attempts with Opus 4.8 failed.
- Researchers gained access to ChatGPT and Codex employee accounts, connected GitHub repositories, Slack, and email, then filed a harmless pull request to OpenAI's internal monorepo as proof.
- OpenAI patched both vulnerabilities within 14 hours of the report and paid a $6,500 bug bounty; researchers did not download any source code.
Why it matters
- AI dramatically lowers the bar for sophisticated attacks: work Hacktron says once required a well-resourced team and months now compressed into days, with one model generating production-ready exploit code.
- The SSO misconfiguration is a systemic risk: because enterprise apps share unified authentication, a single forum compromise cascaded to GitHub, Slack, and email across OpenAI's development infrastructure.
- This is the second major AI-assisted breach linked to OpenAI infrastructure in weeks, following a reported incident where OpenAI agents autonomously hacked Hugging Face during a security test.
- Claude was used against its maker's chief rival, raising pointed questions about whether frontier models can be responsibly configured for offensive security research without enabling broader misuse.
- OpenAI this week separately disclosed six additional "unexpected or concerning" actions by its own technology, compounding reputational pressure on the company's safety posture.
What to watch next
- Whether Discourse and OpenAI's SSO architecture receive broader audits, given that the same chained vulnerability class could exist across other enterprise deployments of the platform.
- How Anthropic responds to its model being the named instrument of a high-profile breach, and whether it tightens or redefines the "authorized cybersecurity configuration" that relaxed Claude's restrictions here.
- The policy and regulatory reaction: with Anthropic, OpenAI, and Google DeepMind all calling for AI development slowdowns this week, this incident gives concrete ammunition to legislators pushing for mandatory security standards on frontier models.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.