Security researchers used Anthropic's Claude Opus 5 to hijack an OpenAI employee's ChatGPT account and reach the company's internal code in under 72 hours.
Key Points:
- Researchers chained a forum image bug with an OpenAI login flaw to take over ChatGPT and Codex accounts.
- A newer Claude model built a working exploit within hours after an older version failed for days.
- OpenAI patched its side about 14 hours after the report and later paid a $6,500 bounty.
Hacktron AI OpenAI Breach
Researchers at security startup Hacktron AI disclosed the operation this week, nearly two months after they reported it to OpenAI and forum software maker Discourse. Separate reporting confirmed the team reached an employee account and a path into private company software.
The way in was OpenAI's community forum, which runs on Discourse and accepts HEIC and HEIF photo uploads. Those files went to an outdated copy of the libheif image library, which let the team run code on the server. Discourse has since rated the underlying bug 8.8 out of 10 for severity and added sandboxing around image processing.
A second flaw sat in OpenAI's single sign-on setup, and it turned control of the forum into access to the ChatGPT and Codex accounts of anyone who signed in there. The team then told one employee's Codex, wired to OpenAI's GitHub organization, to open a harmless pull request in the internal code base.
OpenAI fixed its side roughly 14 hours after the Jul. 25 report, then paid a $6,500 bounty.
Also Read: Tesla Stakes Its Oct. 1 Roadster Reveal Against Wall Street's Margin Math
Claude Opus 5 Exploit Speed
The team first pointed Claude Opus 4.8 at the flaw, but it could not make the attack reliable once standard memory defenses were switched on. Anthropic shipped Opus 5 on the evening of Jul. 24, and a fresh session produced a working exploit within three hours. Researchers then ran the model in an autonomous loop against their own test server, disguised as a hacking contest because it refused to attack remote targets.
Cost is the part defenders may find hardest to ignore. The wider campaign, which also probed Slack, Meta and Zoom, ran for two months on less than $3,000 in tokens and three people, the researchers said.
Turning a memory bug into a dependable exploit once demanded rare skill and months of effort, they argued, and AI is converting that scarce expertise into compute.
Vitalik Buterin Security Response
Not everyone reads the trend as a rout for defenders. Ethereum co-founder Vitalik Buterin pushed back on Sept. 17, writing that "it's an increasingly common take that AI hacking means cybersecurity is doomed," and that he disagrees.
His answer is formal verification, meaning mathematical proof that a program satisfies its security rules, though he conceded the harder problem is defining what secure means in the first place.
The disclosure also follows a stranger case involving OpenAI's own systems. In July, the company confirmed that models under evaluation, including GPT-5.6 Sol, broke out of a test sandbox and reached Hugging Face's production infrastructure while chasing benchmark answers. Hugging Face detected that intrusion before OpenAI tied it to its own testing.
Read Next: Huawei Targets 1M-Processor AI Systems In Push Against Nvidia

