
A three-person team has hacked OpenAI after they used Anthropic’s Claude to help exploit a flaw linked to the company’s community forum. The team gained access to an OpenAI employee’s ChatGPT account and reached the company’s internal GitHub environment before reporting the issue to OpenAI.
Here are the details of the Hack.
On X, AI researcher s1r1us confirmed that the team breached OpenAI on July 25, 2026.
The Hacktron AI team chained two vulnerabilities to take over ChatGPT and Codex accounts linked to OpenAI employees and some unrelated users. These accounts also had access to connected services such as Outlook, Slack, and GitHub.
The team said the entire process from finding the vulnerability to reaching OpenAI’s internal repository took less than 72 hours.
“On July 25, we hacked OpenAI. It took us <72h.”
As proof, we created a pull request in OpenAI’s internal codebase.
The attack began on July 23 with a vulnerability in the image-processing system used by Discourse, the third-party software hosting OpenAI’s community forum.
The team first used Claude Opus 4.8 to help build an exploit, but the model struggled to bypass address-space layout randomization, a security feature designed to make memory attacks harder.
After Anthropic released Claude Opus 5 the next day, the researchers switched models and said it helped them create a working ARM64 exploit within hours.
The exploit allowed the team to steal active authentication tokens from the discussion server. They then used those credentials to access an OpenAI employee account and reach private GitHub repositories. The researchers said the full attack chain took less than 72 hours.
OpenAI confirmed the incident and said it narrowed permissions on community sign-in tokens, revoked affected sessions, and fixed the image-processing flaw. The company said no customer data or proprietary AI model weights were compromised.
Discourse also patched the underlying vulnerability and added additional protection around image processing.
The breach was carried out by a three-person team of cybersecurity researchers from Hacktron AI. The team found and exploited the security flaws as part of an authorized white-hat bug bounty program, not as a criminal attack.
Meanwhile, OpenAI later paid the researchers a $6,500 bounty for reporting the vulnerabilities.
Solana price is holding above the $100 support zone as traders assess whether its latest…
The Bank of Japan (BOJ) raised its benchmark interest rate by 25 basis points to…
Uniswap price surged from around $6.63 to $8.49 as traders reacted to a major shift…
On September 18, 2026, the KOSPI index traded sharply higher in morning session, reaching around…
The Bank of Japan hiked its policy rate by 25 basis points to 1.25%, the…
Near Protocol (NEAR) is making waves in the DeFi space after launching the industry's first…