Researchers reportedly used Claude Opus 5 to take over OpenAI employee accounts
A post citing Hacktron AI says three researchers chained forum and single sign-on flaws in July 2026, using Claude Opus 5, under 72 hours and less than $3,000 in tokens.
TLDR
According to a post citing Hacktron AI, the July 2026 exploit was disclosed that September. Three researchers reportedly used Claude Opus 5 to develop a chain starting with an HEIF image on OpenAI’s Discourse forum. The account describes a libheif memory flaw that enabled remote code execution through ImageMagick, followed by a single sign-on flaw that allowed takeovers of employees’ ChatGPT/Codex accounts. Through Codex’s connection to internal GitHub, the researchers reportedly opened a proof-of-concept pull request without reading private code. The post says OpenAI fixed the issues in about 14 hours and lists a $6,500 bounty for the single sign-on finding; Discourse was outside the bounty program’s scope.
Combined views
65
1 Source, first seen ago