Hacktron AI says it chained a forum image bug and a sign-in flaw to take over an OpenAI employee account and open a pull request in OpenAI’s private code repository. OpenAI and Discourse fixed the flaws, and OpenAI paid a $6,500 bounty.
New to this? Read it in simple words
- Security start-up Hacktron AI says Anthropic’s Claude Opus 5 helped it reach OpenAI’s private code. The attack began with one image uploaded to OpenAI’s public forum.
- A sign-in flaw then let the researchers take over an OpenAI employee’s account. The flaws were fixed, and OpenAI paid a $6,500 bug bounty.
- AI can shorten the time between a public flaw and a working attack. That makes fast updates more important.
- Hacktron says the older Opus 4.8 could not build the attack, but Opus 5 could. Nobody has repeated this comparison independently.
- Bug bounty
- Money a company pays people who find and report security flaws.
The attack chain began on a public forum
Researchers from Hacktron AI, a three-person start-up, published a detailed report on how they reached OpenAI’s internal code. Their chain started on OpenAI’s community forum, which runs on Discourse software.
They uploaded a specially made HEIF image, a common photo format. The forum processed it with image libraries that had a known flaw. That let the researchers run their own code on the forum server.
A second flaw, in OpenAI’s sign-in system, then let them take over an OpenAI employee’s ChatGPT and Codex account. That Codex account was connected to OpenAI’s GitHub. The team used it to open a pull request in OpenAI’s private main repository as proof. They say they did not look at sensitive code.
Hacktron says Claude Opus 5 built the key exploit. OpenAI and Discourse fixed the flaws in July.
The researchers say a newer Claude model made the difference
Hacktron says Anthropic’s earlier Opus 4.8 model failed to build a working exploit over several sessions. It says Opus 5 succeeded within hours of its release on the evening of July 24.
VentureBeat reports that Opus 5 first built a working exploit for ARM computer chips. It then changed the exploit to work on the forum’s x86 server, which manages memory in a different way.
This comparison comes only from Hacktron’s account. Nobody has repeated it independently, and the coverage we read included no comment from Anthropic.
Fast fixes, a small bounty, and a bigger warning
Hacktron reported the problem to OpenAI on July 25. OpenAI confirmed a fix about 14 hours later. Discourse, the maker of the forum software, was told the same day and had a fix by July 27.
OpenAI says it narrowed the permissions of its forum sign-in tokens and cancelled affected sessions. It paid a $6,500 bug bounty on September 1. NBC News reports no evidence that other attackers used the same flaws.
Discourse’s security advisory links the image flaw to a known, published vulnerability in the libheif image library. AI can shorten the time between a public flaw and a working attack. That makes fast updates and tight account permissions more important.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1
- 2
- 3
- 4Research · September 17, 2026OpenAI hacked by small team of white hat security researchers using Anthropic’s Claude Opus 5 VentureBeat
- 5Research · September 18, 2026Hackers breached OpenAI, adding to fever pitch of security and safety concerns NBC News
We read Hacktron’s full write-up and Discourse’s security advisory, then compared them with TechCrunch, VentureBeat, and NBC News. The claim that Opus 5 succeeded where Opus 4.8 failed comes only from the researchers. We describe the access as one opened pull request, because that is what the evidence shows.