Get the app
Industry

Researchers used Claude to break into OpenAI's code in 72 hours

Hacktron chained a Discourse image bug and an over-scoped SSO token into OpenAI's monorepo — Opus 5 wrote the exploit Opus 4.8 couldn't.

Researchers used Claude to break into OpenAI's code in 72 hours

The channel post says Claude Opus 4.8 did it, but that's not quite right. The three-person Hacktron AI team first tried a special cyber-research build of 4.8, and it failed to produce a working exploit across several sessions. Opus 5 succeeded on the same problem within hours of its release. From there, the team was inside OpenAI's internal monorepo in under 72 hours.

The way in: OpenAI's community forum runs on Discourse, which couldn't handle HEIC/HEIF images itself and passed them to ImageMagick and then libheif. libheif had a memory bug that was fixed upstream a year earlier. Nobody flagged it as a security issue, so it never got a CVE, and here it allowed remote code execution on the forum server. The forum's sign-in tokens carried full API access to ChatGPT and Codex accounts, including those of OpenAI employees. One employee's Codex was linked to OpenAI's GitHub organization. The team used it to open a harmless pull request that edited a README, then stopped.

OpenAI says its review found only "limited reads" of private-repo metadata and commits, and no exposed model weights. It narrowed the forum token permissions and revoked affected sessions within about 14 hours. Discourse shipped a fix in two days and now sandboxes image processing. The bounty was $6,500.

Why it matters: a boring image-parser bug plus one over-permissioned token was enough, and frontier models can now write the exploit in hours.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play