Three Researchers Breached OpenAI Staff Accounts Using Claude AI in Under 72 Hours

Reviewed byNidhi Govil

10 Sources

Share

Three Hacktron researchers used Anthropic's Claude Opus 5 to chain two vulnerabilities and access OpenAI employee accounts and internal code repository in under 72 hours. OpenAI patched the single sign-on flaw within 14 hours and paid a $6,500 bug bounty, but the incident exposes how AI security risks are accelerating faster than defenses.

AI Security Breach Exposes Frontier Labs Vulnerabilities

Three researchers at cybersecurity firm Hacktron—Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—demonstrated how Anthropic Claude could be weaponized to breach OpenAI's systems

1

. The team chained two security flaws to access OpenAI staff accounts and an internal code repository in under 72 hours, spending less than $3,000 on AI tokens

5

. This AI-assisted cyberattack wasn't malicious—the researchers conducted responsible disclosure, reported findings to OpenAI, and received a $6,500 bug bounty

2

. OpenAI confirmed the fix approximately 14 hours after notification

1

. Yet the episode raises urgent questions about whether frontier labs have adequate technical guardrails to match their claims about transformative AI capabilities.

How the Attack Chain Worked Through Chained Security Flaws

Source: Hacker News

Source: Hacker News

The OpenAI breach began at community.openai.com, the company's public help forum running on third-party software Discourse

4

. Hacktron discovered that specially crafted HEIC and HEIF image files could exploit a vulnerability in libheif, the image-processing library used by Discourse

1

. The flaw, tracked as CVE-2026-32882 and scored 8.8 out of 10, enabled remote code execution on the forum server

1

. Upstream fixes existed in libheif 1.22.0 since May 2026, but Debian 12 distributions still shipped the vulnerable version 1.19.7 when researchers tested in July

1

.

Control of the forum server alone wouldn't have reached OpenAI's internal systems. The critical second vulnerability was a single sign-on flaw in OpenAI's identity architecture

2

. The forum offered a "Sign in with OpenAI" option—the same SSO that staff used elsewhere

1

. Once researchers compromised the forum server, shared login credentials let them take over ChatGPT and Codex accounts of forum members who were OpenAI employees, without victims taking any action

1

. Hacktron emphasized this was an OpenAI identity problem, not a Discourse flaw—any service using the same sign-on could have granted identical access

1

.

Claude Opus 5 Accelerated Exploitation as Force Multipliers

Source: PYMNTS

Source: PYMNTS

The researchers initially tried Claude Opus 4.8, which struggled to build working exploits when standard memory defenses like ASLR were enabled

1

. Anthropic released Claude Opus 5 on the evening of July 24, and within hours the model produced functional exploit code

1

. Pedhapati estimated the hack would have taken him two to three months working alone without AI assistance

4

. "As the models progress, they become very capable in cyber," Pedhapati explained, describing each new model as "a force multiplier" empowering offensive security work

4

.

Opus 5 shipped with safeguards designed to prevent writing exploit code for real targets

1

. Hacktron circumvented these by pointing the model at their own test server, disguised as a capture-the-flag practice target, then running it in an automated loop

1

. Still, they stressed the work wasn't hands-off—skilled human direction remained essential

1

. Anthropic has reported that criminal and state-backed groups are already using Claude models for real intrusions beyond answering questions

1

.

What Access to Internal Code Repository Could Have Reached

When one employee's Codex link to OpenAI's GitHub opened, it triggered a single pull request in the internal code repository

1

. Hacktron deliberately limited their actions—they didn't read source code, merge or ship anything, or touch customer data

1

. However, the potential reach was far larger. Because staff connects services to ChatGPT and Codex, the same access could theoretically have extended to GitHub, Slack, and email

1

. "Everything that you're talking to ChatGPT [about]—we could leak it. We could get access to it," Pedhapati said, noting they could see whatever conversations users were having, including private discussions

4

.

Bug Bounty Economics Don't Match Claimed AI Risks

OpenAI paid Hacktron $6,500, recognizing "the OpenAI-side finding, not the actions against Discourse," since testing the forum fell outside its bug bounty program

1

. That payment for access reaching employee accounts and an internal code repository at a company valued in the hundreds of billions appears disproportionate

2

. This fits a documented pattern where Anthropic, Google, and Microsoft paid bounties on agent vulnerabilities without publishing flaws, in one case paying $100 on an issue rated above nine out of ten for severity

2

. Bounty economics signal what an industry thinks a bug class is worth—on that measure, the signal remains weak

2

.

Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, called the incident a "warning shot"

3

. "If three responsible researchers armed with commercial AI tools could achieve this level of access in days, we have to assume well-resourced foreign intelligence services are pursuing the same targets continuously and certainly never tipping off the target," Cilluffo said

3

.

Researchers Question OpenAI's Security Posture Against AI Threats

Pedhapati questioned whether OpenAI's security measures align with its stated concerns about AI risks. "If the people building these systems truly believe they are powerful enough to create nuclear-level risks, and they are talking about slowing down because of those risks, why is that work...done through ordinary SAAS products," he posted

3

. He argued that companies like OpenAI need to assume everyone can hack them and build accordingly, adding that "many of the labs are not doing it well" and are "speed running"

4

.

Source: CBS

Source: CBS

OpenAI President Greg Brockman revealed that after the July incident, the company redirected substantial engineering resources toward security. "We took 25 percent of our production engineers and said, 'Sorry, all your projects are on hold. You are now defending.' We found a number of serious issues, and we fixed them," Brockman said in a podcast with Andreessen Horowitz

3

.

What Researchers Say About Middle Ground Between Security Communities

Source: CXOToday

Source: CXOToday

Sayash Kapoor and Arvind Narayanan published an essay on September 14 arguing for "a middle ground between the cybersecurity and AI safety communities"

2

. They describe incidents as fair to call misalignment and reject the view that applying thirty-year-old security methods alone will suffice

2

. Their recommendations include sandboxing, least privilege, logging, tripwires, shutdown mechanisms, and real-time monitoring tested against offensive agents

2

. They also call for liability, mandatory incident reporting including near misses, independent auditing, whistleblower protections, and safe harbors for safety research

2

. Critically, they corrected their own earlier position, saying they are no longer confident the industry is on track to take basic control precautions

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved