Researchers Used Claude to Breach OpenAI in Under 72 Hours
A three-person Hacktron team chained a libheif overflow and an SSO flaw to reach OpenAI's internal repos, using Claude to build the exploit. OpenAI paid a $6,500 bounty.

Researchers Used Claude to Breach OpenAI in Under 72 Hours
A three-person team at the security startup Hacktron chained two vulnerabilities to compromise OpenAI employee accounts and reach the company's internal code repositories. They used Anthropic's Claude models to build the exploit. From first discovery to repository access took less than 72 hours, and OpenAI paid the researchers a $6,500 bounty.
What actually happened
The disclosure, published this week by Hacktron and picked up across security coverage, describes an attack that started somewhere unglamorous: a profile-picture upload on OpenAI's community forum.
- OpenAI's forum runs on Discourse, which handed HEIC/HEIF images to an outdated
libheiflibrary for conversion. A crafted image triggered a heap buffer overflow and gave the researchers remote code execution on the forum server. - From there they exploited an SSO misconfiguration in OpenAI's identity setup. Because "Sign in with OpenAI" tied the forum to ChatGPT and Codex accounts, hijacked session tokens let them impersonate a real OpenAI employee.
- To prove the access without reading any source code, they used the employee's connected Codex to open a harmless pull request in OpenAI's internal
openai/openaimonorepo, then stopped and reported.
The team — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — reported through OpenAI's bug bounty program. OpenAI confirmed a fix about 14 hours after submission. Discourse patched within days and added image-processing sandboxing.
The part enterprise security teams should sit with
The vulnerabilities themselves are serious but familiar. The uncomfortable part is the economics.
Hacktron ran Claude in an autonomous loop to write and refine the memory-corruption exploit. An earlier model struggled across several sessions to produce a working exploit with modern memory protections turned on. Within hours of a newer model's release, the same problem went in and it succeeded. The team's wider campaign against the same image library — reaching Slack, GitHub Enterprise, Rails and several Node.js frameworks — cost under $3,000 in tokens and was run by three people.
Hacktron's own framing is the line worth keeping. Turning a known bug into a reliable exploit used to take rare expertise, real time, and knowledge of the target. That was never a true security boundary, but in practice it protected ordinary companies. AI is converting that scarce expertise into compute.
What to do about it
Two things follow directly for anyone defending a large environment.
Patch the boring dependency first. If your applications accept user-supplied .heic, .heif or .avif images, the libheif path is a live exposure. Update through your distribution's security channel, and sandbox or disable untrusted image decoding wherever you do not need it.
Then revisit the threat model. Assume that turning a public vulnerability into a working exploit is now cheap and fast, rather than something only a well-resourced attacker can pull off. "Someone would have to be very skilled and very patient to exploit this" is exactly the assumption that just got cheaper to break.
Source: A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories (Hacktron)