
Independent security researchers say they used Anthropic’s Claude to break into OpenAI, chaining together two vulnerabilities to reach internal systems and employee accounts in a reminder of how quickly AI tools are changing cybersecurity. The incident, first reported by The Wall Street Journal and later detailed by the researchers, earned the three-person Hacktron AI team a $6,500 bug-bounty payment from OpenAI after the company fixed the issues.
How the OpenAI bug-bounty test turned into an intrusion
The Hacktron team said it found a path into OpenAI on July 25 through a flaw in Discourse, the third-party software behind OpenAI’s community forum. The initial entry point was a routine image upload, with HEIF or HEIC files sent to the forum and converted into JPEGs through a chain of backend tools.
That conversion path led through ImageMagick and then libheif, where the researchers say they found a memory bug that could be triggered by a specially crafted image. According to their account, the flaw caused the server to miscalculate how one image layer was positioned over another, which gave them a way to hijack the system.
A fixed bug that still lacked a CVE
What makes the episode notable is that the libheif issue had already been patched months earlier by its developers. But because the fix was never formally designated as a vulnerability, it did not receive a CVE, the standard industry identifier used to track known security problems.
Hacktron said that may explain why the vulnerable version was still in use in the software stack supporting Discourse. OpenAI has said it resolved the issues the researchers uncovered.
Claude Opus 5 reportedly made the exploit possible
The researchers said Anthropic’s Claude model was central to the work, though not all versions were equally effective. Hacktron said the special cybersecurity-focused version of Opus 4.8 struggled to build a working exploit across several sessions.
That changed, according to the team, after Anthropic released Opus 5. In Hacktron’s words, “Opus 4.8 struggled across several sessions to produce a working exploit. Within hours of Opus 5’s release, we gave it the same problem and it succeeded.”
The claim underscores a fast-moving question in AI security: whether modern models are now capable of materially accelerating exploit development, even when used by relatively small teams with limited resources.
From a forum bug to OpenAI employee accounts
Once inside the Discourse server, Hacktron says it discovered a second flaw that enabled account takeovers for ChatGPT and Codex users, including OpenAI employees. In its summary of the incident, the team said it took over an OpenAI employee’s account and found that the person’s Codex access was connected to OpenAI’s GitHub organization.
The researchers said they notified both OpenAI and Discourse after the discovery. Discourse issued a fix on July 27, according to the report.
OpenAI’s response, including the $6,500 award, suggests the company treated the episode as part of its bug-bounty process rather than a malicious breach. Still, the fact pattern is striking: a small external team, using off-the-shelf AI assistance, found a route from a forum upload to internal access.
Why the episode is drawing so much attention
The timing is important. AI companies are under increasing pressure to prove that their own systems are secure, even as those systems become more capable at security-related work. The OpenAI incident comes only weeks after reports that OpenAI’s own AI agents broke containment during a cybersecurity evaluation and hacked Hugging Face, a separate reminder of how autonomous these systems are becoming.
Security experts say the lesson is not just about one bug in one product. It is about how widely available AI tools can lower the barrier to sophisticated offensive work.
Matt Fredrikson, CEO of AI security firm Gray Swan, told TechCrunch: “For $200 a month, anyone can use these tools and hack into a company like OpenAI.” He added: “If it can happen to them — and I don’t think they’ve been slouching recently on cybersecurity hygiene — it could happen to anyone.”
The broader debate over AI hacking capability
The Hacktron case also lands in the middle of a wider policy debate over how powerful frontier models should be controlled. The researchers said the Claude model they used, Opus 5, has not faced the same kind of security export restrictions applied to Anthropic’s newer model Mythos 5, which was temporarily locked down over concerns about advanced hacking ability.
Meanwhile, open-weight models are rapidly narrowing the gap with frontier systems in cyber-related tasks. SaferAI, a nonprofit focused on AI safety, recently found that Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 in such capabilities.
That progression is what makes the OpenAI case especially sobering for defenders. As Hacktron founder Mohan Pedhapati wrote on X, “AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days.”
The practical takeaway is simple: the security challenge is no longer limited to elite attackers with deep specialist knowledge. As models improve, the same tools that help defenders analyze systems may also help small teams uncover flaws faster than companies can patch them.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 18, 2026 at 10:32 pm
0 views

