Researchers used Claude to break into OpenAI's code in 72 hours
Hacktron chained a Discourse image bug and an over-scoped SSO token into OpenAI's monorepo — Opus 5 wrote the exploit Opus 4.8 couldn't.

The channel post says Claude Opus 4.8 did it, but that's not quite right. The three-person Hacktron AI team first tried a special cyber-research build of 4.8, and it failed to produce a working exploit across several sessions. Opus 5 succeeded on the same problem within hours of its release. From there, the team was inside OpenAI's internal monorepo in under 72 hours.
The way in: OpenAI's community forum runs on Discourse, which couldn't handle HEIC/HEIF images itself and passed them to ImageMagick and then libheif. libheif had a memory bug that was fixed upstream a year earlier. Nobody flagged it as a security issue, so it never got a CVE, and here it allowed remote code execution on the forum server. The forum's sign-in tokens carried full API access to ChatGPT and Codex accounts, including those of OpenAI employees. One employee's Codex was linked to OpenAI's GitHub organization. The team used it to open a harmless pull request that edited a README, then stopped.
OpenAI says its review found only "limited reads" of private-repo metadata and commits, and no exposed model weights. It narrowed the forum token permissions and revoked affected sessions within about 14 hours. Discourse shipped a fix in two days and now sandboxes image processing. The bounty was $6,500.
Why it matters: a boring image-parser bug plus one over-permissioned token was enough, and frontier models can now write the exploit in hours.
Sources
Independent coverage
- Researchers used Anthropic's Claude to hack into OpenAI techcrunch.com
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code securityweek.com
Written by an AI pipeline from the sources above. Methodology · Report an error
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.