In brief

Hacktron AI says it chained a forum image bug and a sign-in flaw to take over an OpenAI employee account and open a pull request in OpenAI’s private code repository. OpenAI and Discourse fixed the flaws, and OpenAI paid a $6,500 bounty.

New to this? Read it in simple words
  • Security start-up Hacktron AI says Anthropic’s Claude Opus 5 helped it reach OpenAI’s private code. The attack began with one image uploaded to OpenAI’s public forum.
  • A sign-in flaw then let the researchers take over an OpenAI employee’s account. The flaws were fixed, and OpenAI paid a $6,500 bug bounty.
  • AI can shorten the time between a public flaw and a working attack. That makes fast updates more important.
  • Hacktron says the older Opus 4.8 could not build the attack, but Opus 5 could. Nobody has repeated this comparison independently.
Words to know
Bug bounty
Money a company pays people who find and report security flaws.

The attack chain began on a public forum

Researchers from Hacktron AI, a three-person start-up, published a detailed report on how they reached OpenAI’s internal code. Their chain started on OpenAI’s community forum, which runs on Discourse software.

They uploaded a specially made HEIF image, a common photo format. The forum processed it with image libraries that had a known flaw. That let the researchers run their own code on the forum server.

A second flaw, in OpenAI’s sign-in system, then let them take over an OpenAI employee’s ChatGPT and Codex account. That Codex account was connected to OpenAI’s GitHub. The team used it to open a pull request in OpenAI’s private main repository as proof. They say they did not look at sensitive code.

Sources124

ATTACK CHAIN 04
One image upload led, step by step, to a pull request in OpenAI’s private code.

Hacktron says Claude Opus 5 built the key exploit. OpenAI and Discourse fixed the flaws in July.

The researchers say a newer Claude model made the difference

Hacktron says Anthropic’s earlier Opus 4.8 model failed to build a working exploit over several sessions. It says Opus 5 succeeded within hours of its release on the evening of July 24.

VentureBeat reports that Opus 5 first built a working exploit for ARM computer chips. It then changed the exploit to work on the forum’s x86 server, which manages memory in a different way.

This comparison comes only from Hacktron’s account. Nobody has repeated it independently, and the coverage we read included no comment from Anthropic.

Sources134

Fast fixes, a small bounty, and a bigger warning

Hacktron reported the problem to OpenAI on July 25. OpenAI confirmed a fix about 14 hours later. Discourse, the maker of the forum software, was told the same day and had a fix by July 27.

OpenAI says it narrowed the permissions of its forum sign-in tokens and cancelled affected sessions. It paid a $6,500 bug bounty on September 1. NBC News reports no evidence that other attackers used the same flaws.

Discourse’s security advisory links the image flaw to a known, published vulnerability in the libheif image library. AI can shorten the time between a public flaw and a working attack. That makes fast updates and tight account permissions more important.

Sources1245

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 13, 2026Hacking OpenAI Hacktron AI
  2. 2
    Primary source · July 28, 2026RCE via malformed HEIF file (GHSA-vhm9-85gw-x335) Discourse on GitHub
  3. 3
    Research · September 18, 2026Researchers used Anthropic’s Claude to hack into OpenAI TechCrunch
  4. 4
  5. 5
How we checked this story

We read Hacktron’s full write-up and Discourse’s security advisory, then compared them with TechCrunch, VentureBeat, and NBC News. The claim that Opus 5 succeeded where Opus 4.8 failed comes only from the researchers. We describe the access as one opened pull request, because that is what the evidence shows.