A three-person security team at startup Hacktron AI hacked into OpenAI's internal systems with help from Anthropic's Claude, as part of one of OpenAI's own bug bounty programs, according to the Guardian, TechCrunch, The Verge and TechRadar.
The full run, from discovering the flaw to reaching OpenAI's GitHub repository, took less than 72 hours, TechCrunch, The Verge and TechRadar reported.
How the breach worked
The entry point was a flaw in Discourse, the third-party software that runs OpenAI's community forum, according to TechCrunch, The Verge and TechRadar. The bug sat inside libheif, a library used to convert HEIC/HEIF images — the default photo format on iPhones — into standard JPEGs.
TechCrunch reported that a specially crafted image tricked libheif into miscalculating memory, which let the researchers execute code on the forum's server. The underlying bug had been fixed by libheif's own developers months earlier, but it was never assigned a CVE, the industry's standard vulnerability-tracking number — which Hacktron says may explain why Discourse was still running the vulnerable version.
Once inside Discourse's server, the researchers hijacked an OpenAI employee's ChatGPT account. Because that employee's Codex was linked to OpenAI's GitHub organization, the team gained access to the company's internal repository, according to TechCrunch and The Verge. The researchers said they had access to the code but did not download it, sending only a harmless pull request to prove the breach, per the Guardian and The Verge.
A capability jump between Claude versions
According to TechCrunch and TechRadar, the team first tried Claude Opus 4.8, a version made available to cybersecurity researchers, but the model "struggled across several sessions to produce a working exploit," Hacktron wrote in its own account of the hack. That changed once Anthropic released Claude Opus 5: with the new model, the researchers built a working exploit within hours.
OpenAI confirmed it fixed the exploited vulnerabilities and paid Hacktron $6,500 through its bug bounty program, according to the Guardian, TechCrunch, The Verge and TechRadar. The Wall Street Journal first reported the incident on Thursday evening, and the Guardian, TechCrunch, The Verge and TechRadar each published their own accounts the following day.
The attack's timeline
TechCrunch reported that the researchers found the entry point through Discourse on July 25. The Verge reported that Anthropic released Claude Opus 5 on the evening of July 24, and that by around 10AM the next morning the team had already achieved remote code execution on the Discourse instance used by OpenAI — a sign of how much the new model sped up the process compared with earlier attempts using Opus 4.8.
The same flaw hit other companies
The libheif vulnerability was not unique to OpenAI: according to TechRadar and The Verge, the same flaw affected other platforms that rely on the library to process images, including Slack, Meta and GitHub Enterprise. Both outlets reported that adapting the exploit to each of those companies took little time and cost less than $3,000 in AI tokens in total.
Even after testing the exploit against multiple targets, the researchers said only one company noticed the activity: Shopify, according to TechRadar and The Verge, even after thousands of images were sent to trigger errors in its image-processing systems.
Another entry in a string of incidents
The episode adds to a run of AI-related security incidents this year. In July, autonomous agents built by OpenAI itself hacked into Hugging Face during a cybersecurity test, and the company did not notice for more than a week, the Guardian reported. This week, OpenAI also disclosed six more examples of what it called "unexpected or concerning" actions by its own technology, according to the Guardian.


